MAL-2026-10713

    Dashboard / Malicious Package / MAL-2026-10713

    MAL-2026-10713

    Published: 16 Jul 2026Last Modified: 17 Jul 2026

    Summary: Malicious code in @hibachi-xyz/config (npm)

    Details: Source: amazon-inspector (2012c3b3a43f28209edf1c4b6fdbb0477c7c31f7574e37293cf7dd324f7f1e2f) On require of the package's main entry, top-level code enumerates process.env and collects values whose keys match a credential-shaped regex (KEY, SECRET, TOKEN, PASS, PRIV, SIGN, AWS, CIRCLE, GITHUB, DB, RDS, SENTRY, PYPI, NPM, DOCKER, KUBE, TUNNEL, CF_). It also invokes child_process.execSync to run `whoami && id && cat /proc/1/cgroup` and collects hostname and username. The combined JSON payload is POSTed to https://jorijo.xyz:8443/t with TLS certificate verification disabled (rejectUnauthorized:false). The 99.0.0 version number under the @hibachi-xyz scope is consistent with a version-inflation typosquat or scope hijack of legitimate hibachi packages. Source: ossf-package-analysis (4b4af2f9414079b2062bec53821ecf7f67924011261a4f0430450b8415e9b07e) The OpenSSF Package Analysis project identified '@hibachi-xyz/config' @ 99.0.0 (npm) as malicious. It is considered malicious because: - The package executes one or more commands associated with malicious behavior.

    Affected packages

    Package

    Name: @hibachi-xyz/config

    Purl: pkg:npm/%40hibachi-xyz/config

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    99.0.0
    MAL-2026-10713 | CVE-DB