VYPR

npm · Malicious package advisory

Malware

generate-schema-viem

MAL-2026-15595

Malicious code in generate-schema-viem (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (82b43ea1e723ebd0c0ef5c4cd564b106089f9b5f9fd119dcac26dc1e130a14bf)
Package publishes as `generate-schema-viem` but exposes a bin named `generate-schema-ethers` (a dependency-confusion / typosquat shape against the `generate-schema-*` namespace). On CLI invocation, `bin/cli.js` executes `whoami`, reads `os.hostname()` and platform, and POSTs `{pkg, whoami, hostname, platform}` to the hardcoded endpoint `https://oobme.kunalsharma0553.workers.dev/r/7bq6fz3l15r9`. The manifest's own description self-labels the package as an OOB callback. Installer identity is leaked to an external attacker-controlled endpoint whenever the tool is invoked on a developer machine or CI runner.

## Source: ossf-package-analysis (6300576c16b112520e6a4cde256e38ce14736ec575b8c94e58a0a9163c7dad78)
The OpenSSF Package Analysis project identified 'generate-schema-viem' @ 1.0.0 (npm) as malicious.

It is considered malicious because:

- The package communicates with a domain associated with malicious activity.

- The package executes one or more commands associated with malicious behavior.

Compromised versions (1)

  • 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.