npm · Malicious package advisory
Malwaresm-apikey-model
GHSA-26rf-c87j-mwr4
Malicious code in sm-apikey-model (npm)
Details
**Severity:** Critical **Affected versions:** `= 99.0.0` ## Source: amazon-inspector (d8e5a8bc4d985b445afbc71bd563bcee445381d2539a7110a0ca53d54b800367) package.json declares preinstall and postinstall lifecycle scripts that invoke curl over plain HTTP to a hardcoded bare-IP endpoint (http://16.192.173.5/sm-apikey-model/pre and.../post). The path segment embeds the package name, so the operator of that endpoint receives a callback confirming each host that installed this specific package, along with the installer's source IP. The version number (99.0.0) and the dependency-confusion beacon shape are consistent with a namespace-squat reconnaissance package rather than a functional library. ## Source: ossf-package-analysis (58440b7c774647b07278e54b62e08591a1f106b1e0dfb2f597fd3663512ab427) The OpenSSF Package Analysis project identified 'sm-apikey-model' @ 99.0.1 (npm) as malicious. It is considered malicious because: - The package executes one or more commands associated with malicious behavior. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/69cf85db3ebafc0534169441a15154ec56e73b2b/osv/malicious/npm/sm-apikey-model/MAL-2026-14394.json)) **References:** - https://github.com/ossf/malicious-packages/blob/69cf85db3ebafc0534169441a15154ec56e73b2b/osv/malicious/npm/sm-apikey-model/MAL-2026-14394.json - https://www.npmjs.com/package/sm-apikey-model/v/99.0.0 - https://github.com/advisories/GHSA-26rf-c87j-mwr4
Compromised versions (1)
- = 99.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.