MAL-2026-12350
Malicious code in chart-data-utils (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (3980b39b1ba77c4c8df0b8e08016a299640a60b6255c1ea8be1883343ec750e9) chart-data-utils@1.0.0 advertises itself as a chart data/color helper library (index.js contains only trivial color utilities), but ships a postinstall.js that runs at npm install time and performs credential harvesting and host reconnaissance. The postinstall shells out via child_process.exec to: (1) collect hostname, whoami/id output, Docker/cgroup indicators, sudo -ln, ps aux, ip addr/route; (2) enumerate process environment variables and grep-filter for KEY|TOKEN|SECRET|CREDENTIAL|NPM_TOKEN|AWS_|AZURE|GCP|GITHUB_TOKEN plus GitHub Actions identity fields (GITHUB_TOKEN, GITHUB_REPOSITORY, GITHUB_ACTOR, RUN_ID); (3) probe cloud instance-metadata endpoints at 169.254.169.254 (AWS), 100.100.100.200 (Aliyun), metadata.google.internal (GCP), metadata.tencentyun.com (Tencent), and an internal host tst.woa.com; (4) base64-encode the collected data and POST/GET it over plain HTTP to the hardcoded Burp Collaborator subdomain pzs5w7ntzhsnepwk564lyfdci3oucl0a.oastify.com. The package name/description are a cover story for a CI credential harvester; Chinese-language comments ("分片回传版") in the postinstall reference tst.woa.com.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for chart-data-utils (npm). Pin to a known-safe version or switch to an alternative.