MAL-2026-10448
Dashboard / Malicious Package / MAL-2026-10448
MAL-2026-10448
Summary: Malicious code in @sqlite-group/schema-generator (npm)
Details: Source: amazon-inspector (4d317d08a81d92d85c53ffe33ef8c709b706ed09c1f89b1c6489ac4fbf9f82c8) On require/import, index.js fetches the content of a GitHub Gist (https://gist.github.com/getchainverse/b57a92378ad0a52430137c3b810e7107, retrieved via api.github.com/gists/<id>) and passes the returned JavaScript directly to eval(). The gist is mutable and controlled by an external account with no relationship to SQLite, so any project that loads this package executes whatever code the gist owner chooses at that moment. The package is published under the `@sqlite-group` npm scope with description "simple node for sql fetch" while the author (`guilderguzman`) has no connection to the SQLite project — the scope is a lure to inflate install probability for what is otherwise a bare remote-eval loader. Source: ghsa-malware (ca51b3e7d457381edd70f43454e9bcf913bc07cadac5ac4c15d5258e4e862410) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
References: https://www.npmjs.com/package/@sqlite-group/schema-generator/v/1.0.2, https://github.com/advisories/GHSA-cf6c-6x68-cf8r
Affected packages
Package
Name: @sqlite-group/schema-generator
Purl: pkg:npm/%40sqlite-group/schema-generator
Affected ranges
Type: SEMVER
Events:
