mal-2026-16480

ossf_malicious_packages
Description

--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (1b1ed6ca931448c083b5356eae6ad5af3cce9011d70fce4ce4ad427349991856) a-onesite@99.9.9 ships an empty index.js and no library functionality. Its package.json declares preinstall, preupdate, and test scripts that all invoke wget against http://eoy34oyrep9j5x8.m.pipedream.net with the installer's username ($(whoami)), current working directory ($(pwd)), and hostname ($(hostname)) as query parameters. The preinstall hook fires automatically on `npm install`, sending installer-identifying reconnaissance data over plaintext HTTP to a third-party collection endpoint unrelated to any advertised purpose. The version number (99.9.9) and empty code payload are consistent with a dependency-confusion reconnaissance beacon rather than a functional package.

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

Weaknesses (CWE)
References
Linked Vulnerabilities

No linked vulnerabilities found.

{
  "affected": [
    {
      "database_specific": {
        "cwes": [
          {
            "cweId": "CWE-506",
            "description": "The product contains code that appears to be malicious in nature.",
            "name": "Embedded Malicious Code"
          }
        ],
        "indicators": {
          "evidence_files": [
            {
              "path": "package.json",
              "sha256": "dd1671c200cc2043ad742b44505f30c7f4f7df960f43b874c55bac97604ab5bd",
              "tlsh": "94f050fde838ef4319878f6435614366f0627b6711056c19dbf12d04595c8e134b6554"
            },
            {
              "path": "index.js",
              "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"
            }
          ],
          "package_integrity": [
            {
              "filename": "a-onesite-99.9.9.tgz",
              "hashes": {
                "sha1": "a5222f038b75628e8f0b7657e1a5507f6db41f80",
                "sha512_sri": "sha512-tQdZ6f+dTHDn/BhU+3uJvhaXpoehya97vUbl8dG8BAQlArz6wbSr3/gnG+xhZpDIe24UBWVnpM+QnXR0Xg4p8Q=="
              }
            }
          ]
        }
      },
      "package": {
        "ecosystem": "npm",
        "name": "a-onesite"
      },
      "versions": [
        "99.9.9"
      ]
    }
  ],
  "credits": [
    {
      "contact": [
        "inspector-research@amazon.com"
      ],
      "name": "Amazon Inspector",
      "type": "FINDER"
    }
  ],
  "database_specific": {
    "malicious-packages-origins": [
      {
        "id": "IN-MAL-2026-020495",
        "import_time": "2026-09-23T18:44:13.368503244Z",
        "modified_time": "2026-09-23T18:29:39Z",
        "sha256": "1b1ed6ca931448c083b5356eae6ad5af3cce9011d70fce4ce4ad427349991856",
        "source": "amazon-inspector",
        "versions": [
          "99.9.9"
        ]
      }
    ]
  },
  "details": "\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (1b1ed6ca931448c083b5356eae6ad5af3cce9011d70fce4ce4ad427349991856)\na-onesite@99.9.9 ships an empty index.js and no library functionality. Its package.json declares preinstall, preupdate, and test scripts that all invoke wget against http://eoy34oyrep9j5x8.m.pipedream.net with the installer's username ($(whoami)), current working directory ($(pwd)), and hostname ($(hostname)) as query parameters. The preinstall hook fires automatically on `npm install`, sending installer-identifying reconnaissance data over plaintext HTTP to a third-party collection endpoint unrelated to any advertised purpose. The version number (99.9.9) and empty code payload are consistent with a dependency-confusion reconnaissance beacon rather than a functional package.\n",
  "id": "MAL-2026-16480",
  "modified": "2026-09-23T18:29:39Z",
  "published": "2026-09-23T18:29:39Z",
  "references": [
    {
      "type": "PACKAGE",
      "url": "https://www.npmjs.com/package/a-onesite/v/99.9.9"
    }
  ],
  "schema_version": "1.7.4",
  "summary": "Malicious code in a-onesite (npm)"
}
View JSON API Download JSON