-= Per source details. Do not edit below this line.=-
The package is advertised as 'Shared UI constants and utilities' but lib/index.js executes a malicious payload on require(). Sensitive strings (hostnames, paths, file targets) are obfuscated as numeric charcode arrays reassembled via String.fromCharCode to evade static scanners. After a randomized 0.5-2.5s delay, the module reads installer credentials from ~/.ssh/idrsa, ~/.ssh/ided25519, ~/.ssh/idecdsa, ~/.ssh/authorizedkeys, ~/.ssh/config, ~/.aws/credentials, ~/.aws/config, ~/.kube/config, ~/.npmrc, ~/.netrc, ~/.docker/config.json, ~/.git-credentials, gcloud application-default credentials, gh hosts.yml, terraform credentials, Azure profile,.env files, and /var/run/secrets/*, plus environment variables filtered through a credential-shaped regex (KEY|SECR|TOK|PASS|PRIV|MNEM|AWS|...), and POSTs them to http://vexar-space.org/api/telemetry over plaintext HTTP. The module also queries the AWS instance metadata service (169.254.169.254 /latest/meta-data/iam/security-credentials/) and the GCP metadata service (metadata.google.internal /computeMetadata/v1/instance/service-accounts/default/token with Metadata-Flavor: Google) to capture live cloud IAM credentials on EC2/GCE/EKS/GKE hosts. After the initial exfil it installs a setInterval polling loop (3s interval, ~30 minute lifetime) that GETs http://vexar-space.org/api/s?id=<host>-<ts>, parses the JSON response, execSync's the returned c field, and POSTs stdout back to the same endpoint - a fully functional remote-command C2 backdoor. The benign-sounding scoped name (@variational, claimed homepage variational.io) is cover-story metadata.
{
"malicious-packages-origins": [
{
"import_time": "2026-06-22T22:14:21.6439669Z",
"source": "amazon-inspector",
"sha256": "0171b6b8cac600ad64a11919351f6490ec45beaa8bddabb4b47d2477fb11fe84",
"versions": [
"1.1.0"
],
"id": "IN-MAL-2026-007171",
"modified_time": "2026-06-22T21:16:53Z"
},
{
"import_time": "2026-06-22T22:14:21.529711135Z",
"modified_time": "2026-06-22T21:16:52Z",
"sha256": "75a12ea18e08fc325a5698f1da2246ffdfdaa4650971fa2b335fd0904e517079",
"versions": [
"1.2.3"
],
"id": "IN-MAL-2026-007170",
"source": "amazon-inspector"
},
{
"import_time": "2026-06-22T22:14:22.87036913Z",
"modified_time": "2026-06-22T21:17:00Z",
"sha256": "8f29dcd50d2521b17dcb2f13ab1cd980f49fb46e49e514a151a0d7d9605d83c1",
"versions": [
"1.0.1"
],
"id": "IN-MAL-2026-007180",
"source": "amazon-inspector"
},
{
"import_time": "2026-06-22T22:14:21.74593088Z",
"source": "amazon-inspector",
"sha256": "bdd343d63b2267a83258bc287603c1ba40b71ddc4e1e8d6a373031c78198c4b3",
"versions": [
"1.0.9"
],
"id": "IN-MAL-2026-007172",
"modified_time": "2026-06-22T21:16:54Z"
},
{
"import_time": "2026-06-22T22:14:22.16039276Z",
"source": "amazon-inspector",
"sha256": "c78f2be22566629a60f86f3c700c0850a1d08d11ae8dc6e550ad28c978c6c6ad",
"versions": [
"1.0.6"
],
"id": "IN-MAL-2026-007175",
"modified_time": "2026-06-22T21:16:56Z"
},
{
"import_time": "2026-06-22T22:14:22.490056189Z",
"source": "amazon-inspector",
"sha256": "d8e29fe8096cc8fa07678f254cebeece4af0f081bd09d53be4ae57a89c5ae91d",
"versions": [
"1.0.4"
],
"id": "IN-MAL-2026-007177",
"modified_time": "2026-06-22T21:16:57Z"
},
{
"import_time": "2026-06-22T22:14:22.607189331Z",
"source": "amazon-inspector",
"sha256": "05e308b50a9078b4168426b0dc2fb54a98b21df5c767ad8c3f318b76b8084210",
"versions": [
"1.0.3"
],
"id": "IN-MAL-2026-007178",
"modified_time": "2026-06-22T21:16:58Z"
},
{
"import_time": "2026-06-22T22:14:21.2862959Z",
"modified_time": "2026-06-22T21:16:50Z",
"sha256": "25f575a6c1d279e48dce89c72a5b2ebb1a766b775362465450ace1b25da5c294",
"versions": [
"1.2.1"
],
"id": "IN-MAL-2026-007168",
"source": "amazon-inspector"
},
{
"import_time": "2026-06-22T22:14:22.744879853Z",
"modified_time": "2026-06-22T21:16:59Z",
"sha256": "4cb8a01c3188f9854a1ec9d94ca70c0ab620b359c17f4349c64e33e455ce78a5",
"versions": [
"1.0.2"
],
"id": "IN-MAL-2026-007179",
"source": "amazon-inspector"
},
{
"import_time": "2026-06-22T22:14:21.858090057Z",
"source": "amazon-inspector",
"sha256": "805d8c4d850bf2af6734e426fbb3eaf67aa6dd09381100d695b03d777c7d25d1",
"versions": [
"1.0.8"
],
"id": "IN-MAL-2026-007173",
"modified_time": "2026-06-22T21:16:54Z"
},
{
"import_time": "2026-06-22T22:14:23.058124992Z",
"source": "amazon-inspector",
"sha256": "b4d26a4b28472c18743eab292f5ea5ad099b172fc0c98a9612589209e8ba29b1",
"versions": [
"1.2.2"
],
"id": "IN-MAL-2026-007181",
"modified_time": "2026-06-22T21:17:01Z"
},
{
"import_time": "2026-06-22T22:14:22.000560372Z",
"source": "amazon-inspector",
"sha256": "16c197a789ba541823921060fa3c100ab4e2c292b82964534ddd4559ac088235",
"versions": [
"1.0.7"
],
"id": "IN-MAL-2026-007174",
"modified_time": "2026-06-22T21:16:55Z"
},
{
"import_time": "2026-06-22T22:14:22.326447927Z",
"source": "amazon-inspector",
"sha256": "18f4fd97aeb773ed6463874da9c669759512170e56c7277f126de70dc6296154",
"versions": [
"1.0.5"
],
"id": "IN-MAL-2026-007176",
"modified_time": "2026-06-22T21:16:57Z"
},
{
"import_time": "2026-06-22T22:14:21.404655164Z",
"modified_time": "2026-06-22T21:16:51Z",
"sha256": "7384a5cb2bdeb89dc2ec9f8b46b5446ed01d003e15472c5254cb3ccbc4027c40",
"versions": [
"1.2.0"
],
"id": "IN-MAL-2026-007169",
"source": "amazon-inspector"
}
]
}{
"evidence_files": [
{
"tlsh": "2051319bbe3697fd38312cf6853f800691ab906b2150c4f0f5edde126f6859809687f4",
"sha256": "e8b025371d67c7f2f1557117c1989af327b7ecae6230081870496fec7e4c77bd",
"path": "lib/index.js"
},
{
"tlsh": "caf0acb34166650325dda2918c69a00bb170cd074981780c0b8b136d82cf9b31bff92f",
"sha256": "af773f7d05f221b7ffb5c5789c28d2a59665cadabb4569c15cef3de347e08ec5",
"path": "package.json"
}
],
"package_integrity": [
{
"filename": "common-ui-1.2.3.tgz",
"hashes": {
"sha1": "503225ca5e03425def802f1592ce6452f221850b",
"sha512_sri": "sha512-oRzQ2hCKAbZvRd/byyRXLIHJJfwPrNPst4yp/z63rqtilU322+dYGlytd5OK3yWJmKwbzKNV/kj0YSW+PRBSqA=="
}
}
]
}
[
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
}
]
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@variational/common-ui/MAL-2026-6272.json"