MAL-2026-6272

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@variational/common-ui/MAL-2026-6272.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-6272
Published
2026-06-22T21:16:50Z
Modified
2026-06-22T22:31:22.392392991Z
Summary
Malicious code in @variational/common-ui (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (75a12ea18e08fc325a5698f1da2246ffdfdaa4650971fa2b335fd0904e517079)

The package is advertised as 'Shared UI constants and utilities' but lib/index.js executes a malicious payload on require(). Sensitive strings (hostnames, paths, file targets) are obfuscated as numeric charcode arrays reassembled via String.fromCharCode to evade static scanners. After a randomized 0.5-2.5s delay, the module reads installer credentials from ~/.ssh/idrsa, ~/.ssh/ided25519, ~/.ssh/idecdsa, ~/.ssh/authorizedkeys, ~/.ssh/config, ~/.aws/credentials, ~/.aws/config, ~/.kube/config, ~/.npmrc, ~/.netrc, ~/.docker/config.json, ~/.git-credentials, gcloud application-default credentials, gh hosts.yml, terraform credentials, Azure profile,.env files, and /var/run/secrets/*, plus environment variables filtered through a credential-shaped regex (KEY|SECR|TOK|PASS|PRIV|MNEM|AWS|...), and POSTs them to http://vexar-space.org/api/telemetry over plaintext HTTP. The module also queries the AWS instance metadata service (169.254.169.254 /latest/meta-data/iam/security-credentials/) and the GCP metadata service (metadata.google.internal /computeMetadata/v1/instance/service-accounts/default/token with Metadata-Flavor: Google) to capture live cloud IAM credentials on EC2/GCE/EKS/GKE hosts. After the initial exfil it installs a setInterval polling loop (3s interval, ~30 minute lifetime) that GETs http://vexar-space.org/api/s?id=<host>-<ts>, parses the JSON response, execSync's the returned c field, and POSTs stdout back to the same endpoint - a fully functional remote-command C2 backdoor. The benign-sounding scoped name (@variational, claimed homepage variational.io) is cover-story metadata.

Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2026-06-22T22:14:21.6439669Z",
            "source": "amazon-inspector",
            "sha256": "0171b6b8cac600ad64a11919351f6490ec45beaa8bddabb4b47d2477fb11fe84",
            "versions": [
                "1.1.0"
            ],
            "id": "IN-MAL-2026-007171",
            "modified_time": "2026-06-22T21:16:53Z"
        },
        {
            "import_time": "2026-06-22T22:14:21.529711135Z",
            "modified_time": "2026-06-22T21:16:52Z",
            "sha256": "75a12ea18e08fc325a5698f1da2246ffdfdaa4650971fa2b335fd0904e517079",
            "versions": [
                "1.2.3"
            ],
            "id": "IN-MAL-2026-007170",
            "source": "amazon-inspector"
        },
        {
            "import_time": "2026-06-22T22:14:22.87036913Z",
            "modified_time": "2026-06-22T21:17:00Z",
            "sha256": "8f29dcd50d2521b17dcb2f13ab1cd980f49fb46e49e514a151a0d7d9605d83c1",
            "versions": [
                "1.0.1"
            ],
            "id": "IN-MAL-2026-007180",
            "source": "amazon-inspector"
        },
        {
            "import_time": "2026-06-22T22:14:21.74593088Z",
            "source": "amazon-inspector",
            "sha256": "bdd343d63b2267a83258bc287603c1ba40b71ddc4e1e8d6a373031c78198c4b3",
            "versions": [
                "1.0.9"
            ],
            "id": "IN-MAL-2026-007172",
            "modified_time": "2026-06-22T21:16:54Z"
        },
        {
            "import_time": "2026-06-22T22:14:22.16039276Z",
            "source": "amazon-inspector",
            "sha256": "c78f2be22566629a60f86f3c700c0850a1d08d11ae8dc6e550ad28c978c6c6ad",
            "versions": [
                "1.0.6"
            ],
            "id": "IN-MAL-2026-007175",
            "modified_time": "2026-06-22T21:16:56Z"
        },
        {
            "import_time": "2026-06-22T22:14:22.490056189Z",
            "source": "amazon-inspector",
            "sha256": "d8e29fe8096cc8fa07678f254cebeece4af0f081bd09d53be4ae57a89c5ae91d",
            "versions": [
                "1.0.4"
            ],
            "id": "IN-MAL-2026-007177",
            "modified_time": "2026-06-22T21:16:57Z"
        },
        {
            "import_time": "2026-06-22T22:14:22.607189331Z",
            "source": "amazon-inspector",
            "sha256": "05e308b50a9078b4168426b0dc2fb54a98b21df5c767ad8c3f318b76b8084210",
            "versions": [
                "1.0.3"
            ],
            "id": "IN-MAL-2026-007178",
            "modified_time": "2026-06-22T21:16:58Z"
        },
        {
            "import_time": "2026-06-22T22:14:21.2862959Z",
            "modified_time": "2026-06-22T21:16:50Z",
            "sha256": "25f575a6c1d279e48dce89c72a5b2ebb1a766b775362465450ace1b25da5c294",
            "versions": [
                "1.2.1"
            ],
            "id": "IN-MAL-2026-007168",
            "source": "amazon-inspector"
        },
        {
            "import_time": "2026-06-22T22:14:22.744879853Z",
            "modified_time": "2026-06-22T21:16:59Z",
            "sha256": "4cb8a01c3188f9854a1ec9d94ca70c0ab620b359c17f4349c64e33e455ce78a5",
            "versions": [
                "1.0.2"
            ],
            "id": "IN-MAL-2026-007179",
            "source": "amazon-inspector"
        },
        {
            "import_time": "2026-06-22T22:14:21.858090057Z",
            "source": "amazon-inspector",
            "sha256": "805d8c4d850bf2af6734e426fbb3eaf67aa6dd09381100d695b03d777c7d25d1",
            "versions": [
                "1.0.8"
            ],
            "id": "IN-MAL-2026-007173",
            "modified_time": "2026-06-22T21:16:54Z"
        },
        {
            "import_time": "2026-06-22T22:14:23.058124992Z",
            "source": "amazon-inspector",
            "sha256": "b4d26a4b28472c18743eab292f5ea5ad099b172fc0c98a9612589209e8ba29b1",
            "versions": [
                "1.2.2"
            ],
            "id": "IN-MAL-2026-007181",
            "modified_time": "2026-06-22T21:17:01Z"
        },
        {
            "import_time": "2026-06-22T22:14:22.000560372Z",
            "source": "amazon-inspector",
            "sha256": "16c197a789ba541823921060fa3c100ab4e2c292b82964534ddd4559ac088235",
            "versions": [
                "1.0.7"
            ],
            "id": "IN-MAL-2026-007174",
            "modified_time": "2026-06-22T21:16:55Z"
        },
        {
            "import_time": "2026-06-22T22:14:22.326447927Z",
            "source": "amazon-inspector",
            "sha256": "18f4fd97aeb773ed6463874da9c669759512170e56c7277f126de70dc6296154",
            "versions": [
                "1.0.5"
            ],
            "id": "IN-MAL-2026-007176",
            "modified_time": "2026-06-22T21:16:57Z"
        },
        {
            "import_time": "2026-06-22T22:14:21.404655164Z",
            "modified_time": "2026-06-22T21:16:51Z",
            "sha256": "7384a5cb2bdeb89dc2ec9f8b46b5446ed01d003e15472c5254cb3ccbc4027c40",
            "versions": [
                "1.2.0"
            ],
            "id": "IN-MAL-2026-007169",
            "source": "amazon-inspector"
        }
    ]
}
References
Credits

Affected packages

npm / @variational/common-ui

Package

Name
@variational/common-ui
View open source insights on deps.dev
Purl
pkg:npm/%40variational%2Fcommon-ui

Affected ranges

Affected versions

1.*
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.2.0
1.2.1
1.2.2
1.2.3

Database specific

indicators
{
    "evidence_files": [
        {
            "tlsh": "2051319bbe3697fd38312cf6853f800691ab906b2150c4f0f5edde126f6859809687f4",
            "sha256": "e8b025371d67c7f2f1557117c1989af327b7ecae6230081870496fec7e4c77bd",
            "path": "lib/index.js"
        },
        {
            "tlsh": "caf0acb34166650325dda2918c69a00bb170cd074981780c0b8b136d82cf9b31bff92f",
            "sha256": "af773f7d05f221b7ffb5c5789c28d2a59665cadabb4569c15cef3de347e08ec5",
            "path": "package.json"
        }
    ],
    "package_integrity": [
        {
            "filename": "common-ui-1.2.3.tgz",
            "hashes": {
                "sha1": "503225ca5e03425def802f1592ce6452f221850b",
                "sha512_sri": "sha512-oRzQ2hCKAbZvRd/byyRXLIHJJfwPrNPst4yp/z63rqtilU322+dYGlytd5OK3yWJmKwbzKNV/kj0YSW+PRBSqA=="
            }
        }
    ]
}
cwes
[
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "cweId": "CWE-506",
        "name": "Embedded Malicious Code",
        "description": "The product contains code that appears to be malicious in nature."
    }
]
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@variational/common-ui/MAL-2026-6272.json"