MAL-2026-12350
Dashboard / Malicious Package / MAL-2026-12350
MAL-2026-12350
Summary: Malicious code in chart-data-utils (npm)
Details: Source: amazon-inspector (3980b39b1ba77c4c8df0b8e08016a299640a60b6255c1ea8be1883343ec750e9) [email protected] advertises itself as a chart data/color helper library (index.js contains only trivial color utilities), but ships a postinstall.js that runs at npm install time and performs credential harvesting and host reconnaissance. The postinstall shells out via child_process.exec to: (1) collect hostname, whoami/id output, Docker/cgroup indicators, sudo -ln, ps aux, ip addr/route; (2) enumerate process environment variables and grep-filter for KEY|TOKEN|SECRET|CREDENTIAL|NPM_TOKEN|AWS_|AZURE|GCP|GITHUB_TOKEN plus GitHub Actions identity fields (GITHUB_TOKEN, GITHUB_REPOSITORY, GITHUB_ACTOR, RUN_ID); (3) probe cloud instance-metadata endpoints at 169.254.169.254 (AWS), 100.100.100.200 (Aliyun), metadata.google.internal (GCP), metadata.tencentyun.com (Tencent), and an internal host tst.woa.com; (4) base64-encode the collected data and POST/GET it over plain HTTP to the hardcoded Burp Collaborator subdomain pzs5w7ntzhsnepwk564lyfdci3oucl0a.oastify.com. The package name/description are a cover story for a CI credential harvester; Chinese-language comments ("分片回传版") in the postinstall reference tst.woa.com.
Affected packages
Package
Name: chart-data-utils
Purl: pkg:npm/chart-data-utils
Affected ranges
Type: N/A
Events:
