{"id":"MAL-2026-17327","summary":"Malicious code in exiouss (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (43ce408818d0222061c3b6ed499d77a245aae78e30e4f57c8e6e77ee52705805)\nmain.js in exiouss@5.0.1 imports child_process and issues POST requests to hardcoded endpoints, including https://gemini.google.com and https://ipc.shadxino.internal (main.js around lines 368-386). The presence of an `ipc.shadxino.internal` destination alongside a public Google host, combined with child_process usage and repeated `ping` invocations across the file (lines 202, 340, 420, 583, 611), fits an active-exfiltration/reconnaissance shape rather than any documented HTTP-client behavior. The `.internal` host is not a resolvable public destination and its appearance in a published npm module is consistent with an attacker-side collector or a leaked internal C2 name.\n","modified":"2026-09-30T05:30:07.708423220Z","published":"2026-09-30T04:50:53Z","database_specific":{"malicious-packages-origins":[{"sha256":"43ce408818d0222061c3b6ed499d77a245aae78e30e4f57c8e6e77ee52705805","source":"amazon-inspector","versions":["5.0.1"],"id":"IN-MAL-2026-020811","import_time":"2026-09-30T05:19:45.972923579Z","modified_time":"2026-09-30T04:50:53Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/exiouss/v/5.0.1"}],"affected":[{"package":{"name":"exiouss","ecosystem":"npm","purl":"pkg:npm/exiouss"},"versions":["5.0.1"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"hashes":{"sha1":"38765a0b237be07e8e1032fc06248269d35de083","sha512_sri":"sha512-RwLxTyE/Ll1/HcER3r+3Xpx00YdXcNZzKLn415rPeTf9gIBx1FZiFlqNyiXAss2QQhTvJwl+jOnzgPJKQdZzvw=="},"filename":"exiouss-5.0.1.tgz"}],"evidence_files":[{"tlsh":"a193f75a6065113184336e7a9b3b6c16f7369127e041d354beac83c92fb1419ceb2fee","path":"main.js","sha256":"eca2160ecca05ecbdae57c0b5121799ec1c2e973fdda9e3b07a4ab3c942d0426"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/exiouss/MAL-2026-17327.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}