MAL-2026-4682
Dashboard / Malicious Package / MAL-2026-4682
MAL-2026-4682
Summary: Malicious code in tango-app-api-trax (npm)
Details: Source: amazon-inspector (e7d8f3ef8e6fa016bfc17617ebcedce012c6cce870d89564965a476c3ec8da1c) The tarball contains live, importable credentials for systems other than the installer's own. src/controllers/internalTrax.controller.js hardcodes Lenskart POS authentication (username `tango.eye`, password `55eyetango123`, header `X-Lenskart-API-Key: valyoo123`) inside the exported controllers `aomupdateCollection` and `saleUpdateCollection`, which post to `webservice.pos.lenskart.com` and `central.pos.lenskart.com`. Any consumer of this npm package can use these credentials to authenticate to Lenskart's production POS API as the `tango.eye` partner and read or mutate employee/store data. Additionally, `fir-51e77-firebase-adminsdk-x3sdp-fd902b74ae.json` ships a complete Google Cloud service account (`project_id: tango-trax`, `client_email: [email protected]`) including the `BEGIN PRIVATE KEY` block, granting Firebase Admin privileges over the `tango-trax` GCP project to anyone who pulls the package. There are no install-time lifecycle hooks; the harm is the redistribution of usable third-party credentials, not auto-execution. The `ping` matches in the static analysis are unrelated string occurrences in the controller and not exfiltration behavior.
References: https://www.npmjs.com/package/tango-app-api-trax/v/3.9.10, https://www.npmjs.com/package/tango-app-api-trax/v/3.9.43, https://www.npmjs.com/package/tango-app-api-trax/v/3.9.32, https://www.npmjs.com/package/tango-app-api-trax/v/3.9.39, https://www.npmjs.com/package/tango-app-api-trax/v/3.9.21, https://www.npmjs.com/package/tango-app-api-trax/v/3.9.45, https://www.npmjs.com/package/tango-app-api-trax/v/3.9.47
Affected packages
Package
Name: tango-app-api-trax
Purl: pkg:npm/tango-app-api-trax
Affected ranges
Type: N/A
Events:
