MAL-2026-5570

    Dashboard / Malicious Package / MAL-2026-5570

    MAL-2026-5570

    Published: 11 Jun 2026Last Modified: 11 Jun 2026

    Summary: Malicious code in nim-submit-for-test (npm)

    Details: Source: amazon-inspector (2bf75301042574897cc2f4bd8f3b8939fe4ac7a958f2cfe2404bbbee149797d0) On npm install, the package's postinstall hook executes lib/_compiler.js, which spawns a detached Node process that collects host identity (hostname, username, cwd, IP addresses, npm registry) and the names of environment variables matching NPM|NODE|CI|JENKINS|GIT|BUILD|RUNNER|DOCKER|KUBE|REGISTRY, then POSTs them via https.request to a hardcoded DingTalk webhook (oapi.dingtalk.com/robot/send) with an embedded access token. Before sending, the script checks the installer's username and hostname against an evasion list ('sandbox','malware','analyst','cuckoo','analysis','sample') and exits silently when matched, to avoid running in security analysis environments. The combination of automatic install-time execution, host/CI metadata collection, hardcoded attacker-controlled webhook, and analyst-environment evasion is a clear supply-chain exfiltration beacon.

    Affected packages

    Package

    Name: nim-submit-for-test

    Purl: pkg:npm/nim-submit-for-test

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    2.2.0