MAL-2026-2613
Dashboard / Malicious Package / MAL-2026-2613
MAL-2026-2613
Summary: Malicious code in upstart-offer-container (npm)
Details: Package collects sensitive data (SSH keys, AWS creds, env vars), exfiltrates it to a remote server, and executes shell commands. MALWARE! Source: amazon-inspector (148e48dd7b06a250063027a17895962000ca784a3fe52b704bea049afc85763a) The package upstart-offer-container was found to contain malicious code. Source: ghsa-malware (874e48e71ba19f19b7f284455c8f6a9c102828fa697926226ff59ef260fbc3af) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
References: https://github.com/advisories/GHSA-232r-w3h2-2hv5, https://app.safedep.io/community/malysis/01KP0MRJT822ED96BG601R4XX5
Affected packages
Package
Name: upstart-offer-container
Purl: pkg:npm/upstart-offer-container
Affected ranges
Type: SEMVER
Events:
