MAL-2026-10669
Dashboard / Malicious Package / MAL-2026-10669
MAL-2026-10669
Summary: Malicious code in dbconnectify (npm)
Details: Source: amazon-inspector (e6a41259fb0099de58bc669907fa6fb20331d794b13008df0afb42893808e4ab) The package exposes a method `queryDBConnect` that base64-decodes a hardcoded URL (`HASH_KEY` → https://api.jsonbin.io/v3/b/6a609e63f5f4af5e29b05907), performs an HTTP GET against it, reads a string from the response field `data.record.cookie`, and passes that string to `Module._compile(..., 'errorcheck.js')`, executing it in-process as Node.js code. The destination is a third-party mutable key-value store whose contents the endpoint owner can change at any time, the URL is stored in base64 form rather than as a plain string, the payload is read from a field named `cookie` unrelated to its actual use, and execution errors are silently swallowed. The behavior does not match the package's stated purpose as a database connector and provides arbitrary remote code execution against any caller that invokes the method.
References: https://www.npmjs.com/package/dbconnectify/v/1.0.1, https://www.npmjs.com/package/dbconnectify/v/1.0.2
Affected packages
Package
Name: dbconnectify
Purl: pkg:npm/dbconnectify
Affected ranges
Type: N/A
Events:
