VYPR

npm · Malicious package advisory

Malware

sm-apikey-model

GHSA-26rf-c87j-mwr4

Malicious code in sm-apikey-model (npm)

Details

**Severity:** Critical

**Affected versions:** `= 99.0.0`

## Source: amazon-inspector (d8e5a8bc4d985b445afbc71bd563bcee445381d2539a7110a0ca53d54b800367)
package.json declares preinstall and postinstall lifecycle scripts that invoke curl over plain HTTP to a hardcoded bare-IP endpoint (http://16.192.173.5/sm-apikey-model/pre and.../post). The path segment embeds the package name, so the operator of that endpoint receives a callback confirming each host that installed this specific package, along with the installer's source IP. The version number (99.0.0) and the dependency-confusion beacon shape are consistent with a namespace-squat reconnaissance package rather than a functional library.

## Source: ossf-package-analysis (58440b7c774647b07278e54b62e08591a1f106b1e0dfb2f597fd3663512ab427)
The OpenSSF Package Analysis project identified 'sm-apikey-model' @ 99.0.1 (npm) as malicious.

It is considered malicious because:

- The package executes one or more commands associated with malicious behavior.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/69cf85db3ebafc0534169441a15154ec56e73b2b/osv/malicious/npm/sm-apikey-model/MAL-2026-14394.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/69cf85db3ebafc0534169441a15154ec56e73b2b/osv/malicious/npm/sm-apikey-model/MAL-2026-14394.json
- https://www.npmjs.com/package/sm-apikey-model/v/99.0.0
- https://github.com/advisories/GHSA-26rf-c87j-mwr4

Compromised versions (1)

  • = 99.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.