MAL-2026-10713
Dashboard / Malicious Package / MAL-2026-10713
MAL-2026-10713
Summary: Malicious code in @hibachi-xyz/config (npm)
Details: Source: amazon-inspector (2012c3b3a43f28209edf1c4b6fdbb0477c7c31f7574e37293cf7dd324f7f1e2f) On require of the package's main entry, top-level code enumerates process.env and collects values whose keys match a credential-shaped regex (KEY, SECRET, TOKEN, PASS, PRIV, SIGN, AWS, CIRCLE, GITHUB, DB, RDS, SENTRY, PYPI, NPM, DOCKER, KUBE, TUNNEL, CF_). It also invokes child_process.execSync to run `whoami && id && cat /proc/1/cgroup` and collects hostname and username. The combined JSON payload is POSTed to https://jorijo.xyz:8443/t with TLS certificate verification disabled (rejectUnauthorized:false). The 99.0.0 version number under the @hibachi-xyz scope is consistent with a version-inflation typosquat or scope hijack of legitimate hibachi packages. Source: ossf-package-analysis (4b4af2f9414079b2062bec53821ecf7f67924011261a4f0430450b8415e9b07e) The OpenSSF Package Analysis project identified '@hibachi-xyz/config' @ 99.0.0 (npm) as malicious. It is considered malicious because: - The package executes one or more commands associated with malicious behavior.
Affected packages
Package
Name: @hibachi-xyz/config
Purl: pkg:npm/%40hibachi-xyz/config
Affected ranges
Type: N/A
Events:
