mal-2026-16117

osv_npm
Description

--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (c8aa14d0b9945053b63f4396f09365c5daefec60a25e931f165b3473e7c564f1) The package's preinstall.js lifecycle script runs on npm install and executes host reconnaissance commands (whoami, ipconfig/ip addr, directory listings of C:\ and /, tasklist/ps, and a full environment-variable dump via set/env) and POSTs the collected output over plain HTTP to a hardcoded remote server at 209.126.81.147, using path segments under a canary token 'etoro-nuget-verify1f8eaa57a875'. The package name 'etoro-cashout' at version 99.0.2, the eToro-branded canary, and the beacon path shape are consistent with a dependency-confusion probe targeting an internal eToro registry: any build environment that resolves this public name executes the exfiltration on install. Data leaving the installer includes hostname, username, working directory, filesystem listings, running processes, and the full process environment, which on CI systems routinely contains cloud credentials, registry tokens, and API keys.

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

Weaknesses (CWE)
References
Linked Vulnerabilities

No linked vulnerabilities found.

{
  "affected": [
    {
      "database_specific": {
        "cwes": [
          {
            "cweId": "CWE-506",
            "description": "The product contains code that appears to be malicious in nature.",
            "name": "Embedded Malicious Code"
          },
          {
            "cweId": "CWE-506",
            "description": "The product contains code that appears to be malicious in nature.",
            "name": "Embedded Malicious Code"
          },
          {
            "cweId": "CWE-506",
            "description": "The product contains code that appears to be malicious in nature.",
            "name": "Embedded Malicious Code"
          }
        ],
        "indicators": {
          "evidence_files": [
            {
              "path": "preinstall.js",
              "sha256": "bee47062733940943fd3a66654f0258135fd62911674304ccac11a43226b5f58",
              "tlsh": "ebe027f4118ca6683ccc01c4636b191ed4dfc705bcdec8c04a55d78587b15f1d6115f0"
            }
          ],
          "package_integrity": [
            {
              "filename": "etoro-cashout-999.0.0.tgz",
              "hashes": {
                "sha1": "6be0db8f77a1da1981745fd01e3519c5b6de0965",
                "sha512_sri": "sha512-+oObK225egLxDtxuG7nwvQMvj7+AiKoi7cMQ1rVzqXSNbFE2uQFDFClsPw6xPt/GpoVCnWUT3t/jwft9Nw80sA=="
              }
            }
          ]
        },
        "source": "https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/etoro-cashout/MAL-2026-16117.json"
      },
      "package": {
        "ecosystem": "npm",
        "name": "etoro-cashout",
        "purl": "pkg:npm/etoro-cashout"
      },
      "versions": [
        "999.0.0",
        "99.0.0",
        "99.0.2"
      ]
    }
  ],
  "credits": [
    {
      "contact": [
        "inspector-research@amazon.com"
      ],
      "name": "Amazon Inspector",
      "type": "FINDER"
    }
  ],
  "database_specific": {
    "malicious-packages-origins": [
      {
        "id": "IN-MAL-2026-019915",
        "import_time": "2026-09-10T05:18:06.257486475Z",
        "modified_time": "2026-09-10T04:45:58Z",
        "sha256": "a35bbd75e3cc742fd88d59bcbb64858df0474505b5d6f93f10e8c727c718e129",
        "source": "amazon-inspector",
        "versions": [
          "999.0.0"
        ]
      },
      {
        "id": "IN-MAL-2026-019996",
        "import_time": "2026-09-11T18:21:31.906581633Z",
        "modified_time": "2026-09-11T17:55:21Z",
        "sha256": "a0d8b123f09da5d5d7e0c5f90590e52f5a02d5f1da0b52b4eb5cebd7ecb28071",
        "source": "amazon-inspector",
        "versions": [
          "99.0.0"
        ]
      },
      {
        "id": "IN-MAL-2026-019997",
        "import_time": "2026-09-11T18:21:31.965819313Z",
        "modified_time": "2026-09-11T17:55:29Z",
        "sha256": "c8aa14d0b9945053b63f4396f09365c5daefec60a25e931f165b3473e7c564f1",
        "source": "amazon-inspector",
        "versions": [
          "99.0.2"
        ]
      }
    ]
  },
  "details": "\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (c8aa14d0b9945053b63f4396f09365c5daefec60a25e931f165b3473e7c564f1)\nThe package's preinstall.js lifecycle script runs on npm install and executes host reconnaissance commands (whoami, ipconfig/ip addr, directory listings of C:\\ and /, tasklist/ps, and a full environment-variable dump via set/env) and POSTs the collected output over plain HTTP to a hardcoded remote server at 209.126.81.147, using path segments under a canary token 'etoro-nuget-verify1f8eaa57a875'. The package name 'etoro-cashout' at version 99.0.2, the eToro-branded canary, and the beacon path shape are consistent with a dependency-confusion probe targeting an internal eToro registry: any build environment that resolves this public name executes the exfiltration on install. Data leaving the installer includes hostname, username, working directory, filesystem listings, running processes, and the full process environment, which on CI systems routinely contains cloud credentials, registry tokens, and API keys.\n",
  "id": "MAL-2026-16117",
  "modified": "2026-09-11T18:45:05.112500793Z",
  "published": "2026-09-10T04:45:58Z",
  "references": [
    {
      "type": "PACKAGE",
      "url": "https://www.npmjs.com/package/etoro-cashout/v/999.0.0"
    },
    {
      "type": "PACKAGE",
      "url": "https://www.npmjs.com/package/etoro-cashout/v/99.0.0"
    },
    {
      "type": "PACKAGE",
      "url": "https://www.npmjs.com/package/etoro-cashout/v/99.0.2"
    }
  ],
  "schema_version": "1.9.0",
  "summary": "Malicious code in etoro-cashout (npm)"
}
View JSON API Download JSON