mal-2026-16112

osv_npm
Description

--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (bfe27d37497e77c8f0eca9105a6b64c646c7ef1439c05ec50edaf40215037f92) etoro-analytics@99.0.2 ships a preinstall lifecycle script (preinstall.js) that automatically runs on `npm install`. The script collects installer host identifiers (hostname, username, cwd, platform) and issues an initial HTTP GET to http://209.126.81.147/etoro-nuget-verify1f8eaa57a875/v4/<host>/<user>/<platform>/<cwd>. It then invokes child_process.execSync on platform-branched reconnaissance commands (`whoami /all`, `ipconfig /all`, `tasklist` on Windows; `whoami`, `ifconfig`, `ps aux`, `env` on POSIX) plus home/root directory listings and POSTs the output back to the same hardcoded bare-IP endpoint over plain HTTP. The package name, implausibly high version number (99.0.2), and canary-token URL path are consistent with a dependency-confusion beacon targeting an internal etoro package namespace.

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

Weaknesses (CWE)
References
Linked Vulnerabilities

No linked vulnerabilities found.

{
  "affected": [
    {
      "database_specific": {
        "cwes": [
          {
            "cweId": "CWE-506",
            "description": "The product contains code that appears to be malicious in nature.",
            "name": "Embedded Malicious Code"
          },
          {
            "cweId": "CWE-506",
            "description": "The product contains code that appears to be malicious in nature.",
            "name": "Embedded Malicious Code"
          },
          {
            "cweId": "CWE-506",
            "description": "The product contains code that appears to be malicious in nature.",
            "name": "Embedded Malicious Code"
          }
        ],
        "indicators": {
          "evidence_files": [
            {
              "path": "preinstall.js",
              "sha256": "bee47062733940943fd3a66654f0258135fd62911674304ccac11a43226b5f58",
              "tlsh": "ebe027f4118ca6683ccc01c4636b191ed4dfc705bcdec8c04a55d78587b15f1d6115f0"
            }
          ],
          "package_integrity": [
            {
              "filename": "etoro-analytics-999.0.0.tgz",
              "hashes": {
                "sha1": "43928b907f72071f42a5dd41772529c29f42bcac",
                "sha512_sri": "sha512-w/4jNQk6s6pNO+jcEmK4HnaS15x+OoYxX8WOZn7d3+8rJUa1HloPFNjXWLWwUJ++AiYqBVEHkKclvXdAqbAg4Q=="
              }
            }
          ]
        },
        "source": "https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/etoro-analytics/MAL-2026-16112.json"
      },
      "package": {
        "ecosystem": "npm",
        "name": "etoro-analytics",
        "purl": "pkg:npm/etoro-analytics"
      },
      "versions": [
        "999.0.0",
        "99.0.0",
        "99.0.2"
      ]
    }
  ],
  "credits": [
    {
      "contact": [
        "inspector-research@amazon.com"
      ],
      "name": "Amazon Inspector",
      "type": "FINDER"
    }
  ],
  "database_specific": {
    "malicious-packages-origins": [
      {
        "id": "IN-MAL-2026-019912",
        "import_time": "2026-09-10T05:18:06.103941228Z",
        "modified_time": "2026-09-10T04:44:24Z",
        "sha256": "a87dfbd5f51b30470e8d1df702e746f7c8141fdaafab2237fd1f2ef4897d9ae5",
        "source": "amazon-inspector",
        "versions": [
          "999.0.0"
        ]
      },
      {
        "id": "IN-MAL-2026-020001",
        "import_time": "2026-09-11T18:21:32.172814707Z",
        "modified_time": "2026-09-11T17:55:59Z",
        "sha256": "5273aff85f2243e73b1fb50f228c752d9c22ada7f7d17abae33215e2020e13f9",
        "source": "amazon-inspector",
        "versions": [
          "99.0.0"
        ]
      },
      {
        "id": "IN-MAL-2026-019998",
        "import_time": "2026-09-11T18:21:32.041312459Z",
        "modified_time": "2026-09-11T17:55:35Z",
        "sha256": "bfe27d37497e77c8f0eca9105a6b64c646c7ef1439c05ec50edaf40215037f92",
        "source": "amazon-inspector",
        "versions": [
          "99.0.2"
        ]
      }
    ]
  },
  "details": "\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (bfe27d37497e77c8f0eca9105a6b64c646c7ef1439c05ec50edaf40215037f92)\netoro-analytics@99.0.2 ships a preinstall lifecycle script (preinstall.js) that automatically runs on `npm install`. The script collects installer host identifiers (hostname, username, cwd, platform) and issues an initial HTTP GET to http://209.126.81.147/etoro-nuget-verify1f8eaa57a875/v4/<host>/<user>/<platform>/<cwd>. It then invokes child_process.execSync on platform-branched reconnaissance commands (`whoami /all`, `ipconfig /all`, `tasklist` on Windows; `whoami`, `ifconfig`, `ps aux`, `env` on POSIX) plus home/root directory listings and POSTs the output back to the same hardcoded bare-IP endpoint over plain HTTP. The package name, implausibly high version number (99.0.2), and canary-token URL path are consistent with a dependency-confusion beacon targeting an internal etoro package namespace.\n",
  "id": "MAL-2026-16112",
  "modified": "2026-09-11T18:45:05.126814178Z",
  "published": "2026-09-10T04:44:24Z",
  "references": [
    {
      "type": "PACKAGE",
      "url": "https://www.npmjs.com/package/etoro-analytics/v/999.0.0"
    },
    {
      "type": "PACKAGE",
      "url": "https://www.npmjs.com/package/etoro-analytics/v/99.0.0"
    },
    {
      "type": "PACKAGE",
      "url": "https://www.npmjs.com/package/etoro-analytics/v/99.0.2"
    }
  ],
  "schema_version": "1.9.0",
  "summary": "Malicious code in etoro-analytics (npm)"
}
View JSON API Download JSON