MAL-2026-5570
Dashboard / Malicious Package / MAL-2026-5570
MAL-2026-5570
Summary: Malicious code in nim-submit-for-test (npm)
Details: Source: amazon-inspector (2bf75301042574897cc2f4bd8f3b8939fe4ac7a958f2cfe2404bbbee149797d0) On npm install, the package's postinstall hook executes lib/_compiler.js, which spawns a detached Node process that collects host identity (hostname, username, cwd, IP addresses, npm registry) and the names of environment variables matching NPM|NODE|CI|JENKINS|GIT|BUILD|RUNNER|DOCKER|KUBE|REGISTRY, then POSTs them via https.request to a hardcoded DingTalk webhook (oapi.dingtalk.com/robot/send) with an embedded access token. Before sending, the script checks the installer's username and hostname against an evasion list ('sandbox','malware','analyst','cuckoo','analysis','sample') and exits silently when matched, to avoid running in security analysis environments. The combination of automatic install-time execution, host/CI metadata collection, hardcoded attacker-controlled webhook, and analyst-environment evasion is a clear supply-chain exfiltration beacon.
Affected packages
Package
Name: nim-submit-for-test
Purl: pkg:npm/nim-submit-for-test
Affected ranges
Type: N/A
Events:
