mal-2026-17436
Vulnerability from ossf_malicious_packages
okra-cloud-cdk is a dependency-confusion package: it takes a name that looks like an internal project, uses an inflated version (100.0.0) so it outranks private-registry versions, and runs node setup.js || true as a preinstall script on npm install. setup.js sends the hostname, username, working directory, OS, architecture, Node.js version and configured npm registry, with a per-package tracking token, in an HTTPS POST to https://s85r5k14qk.execute-api.us-east-1.amazonaws.com/prod/hook. The npm account amel10 published okra-cloud-cdk and 9 similar packages within two minutes on 2026-09-30, all with the same setup.js.
- CWE-506 - The product contains code that appears to be malicious in nature.
{
"affected": [
{
"database_specific": {
"cwes": [
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
},
"package": {
"ecosystem": "npm",
"name": "okra-cloud-cdk"
},
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "SEMVER"
}
]
}
],
"credits": [
{
"contact": [
"https://www.invisirisk.com",
"mailto:research@invisirisk.com"
],
"name": "InvisiRisk, Inc.",
"type": "FINDER"
}
],
"database_specific": {
"iocs": {
"domains": [
"s85r5k14qk.execute-api.us-east-1.amazonaws.com"
],
"files": [
{
"digests": {
"sha256": "46efc596e4c935e6ad56282108b76ad18c588cb78558b39fce4e67fb36b0e511"
},
"note": "preinstall: node setup.js || true",
"paths": [
"package.json"
],
"source": "PACKAGE_ARCHIVE"
},
{
"digests": {
"sha256": "c8b43cae12b084d6a8f0270eaae86e202571f31d61cb46f1841c2aab080dc45c"
},
"note": "Executed by the preinstall script.",
"paths": [
"setup.js"
],
"source": "PACKAGE_ARCHIVE"
}
],
"urls": [
"https://s85r5k14qk.execute-api.us-east-1.amazonaws.com/prod/hook"
]
}
},
"details": "okra-cloud-cdk is a dependency-confusion package: it takes a name that looks like an internal project, uses an inflated version (100.0.0) so it outranks private-registry versions, and runs `node setup.js || true` as a preinstall script on npm install. setup.js sends the hostname, username, working directory, OS, architecture, Node.js version and configured npm registry, with a per-package tracking token, in an HTTPS POST to `https://s85r5k14qk.execute-api.us-east-1.amazonaws.com/prod/hook`. The npm account amel10 published okra-cloud-cdk and 9 similar packages within two minutes on 2026-09-30, all with the same setup.js.",
"id": "MAL-2026-17436",
"modified": "2026-09-30T07:12:42Z",
"published": "2026-09-30T07:10:23Z",
"references": [
{
"type": "PACKAGE",
"url": "https://www.npmjs.com/package/okra-cloud-cdk"
}
],
"schema_version": "1.7.4",
"summary": "Malicious code in okra-cloud-cdk (npm)"
}
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.