MAL-2026-17631

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@pinecone-experience/messages/MAL-2026-17631.json
JSON Data
https://api.test.osv.dev/v1/vulns/MAL-2026-17631
Published
2026-10-06T03:57:14Z
Modified
2026-10-06T04:30:48Z
Summary
Malicious code in @pinecone-experience/messages (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (078ce187b38122a7eff5def33454871232cdd38bde7d35e7ee1968d0e98cd45c)

package.json declares its sole dependency ltidisafe as a bare HTTPS tarball URL (https://ltidi.storage.googleapis.com/depenconf/ltidisafe-3.8.3.tgz) hosted on a third-party Google Cloud Storage bucket rather than a registry version range. On npm install, npm fetches that URL and installs whatever bytes it returns, executing any lifecycle scripts inside the fetched tarball on the installer's host with no version pin, no hash, and no integrity check — whoever controls that bucket controls code executed at install time. The shipped index.js is an empty stub (module.exports = {}), so the package's only effect is to pull in the off-registry archive. The package is published under the @pinecone-experience scope at version 99.9.1 — an implausibly high version under a vendor-looking scope, matching the dependency-confusion shape where a high version is used to win resolution against an internal package of the same name.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-021089",
            "import_time":  "2026-10-06T04:22:56.270091881Z",
            "modified_time":  "2026-10-06T03:57:14Z",
            "sha256":  "078ce187b38122a7eff5def33454871232cdd38bde7d35e7ee1968d0e98cd45c",
            "source":  "amazon-inspector",
            "versions":  [
                "99.9.1"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @pinecone-experience/messages

Package

Name
@pinecone-experience/messages
View open source insights on deps.dev
Purl
pkg:npm/%40pinecone-experience/messages

Affected ranges

Affected versions

99.*
99.9.1

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "package.json",
            "sha256":  "3d0f82bc0b4bfb84b1de4e0ed99ebe09770d2fd88a73c004ed0c073bc491d803",
            "tlsh":  "afe07d200a6459330ec611b34c1a6007f3705e4f040dbc0c1fdf041c418ca7328fa35c"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "messages-99.9.1.tgz",
            "hashes":  {
                "sha1":  "4f8b56ad8cc638fef12f675b2c7e8b9bdc2a1d8b",
                "sha512_sri":  "sha512-axbG6UiFQ9shz9HSUlsA6CXEUilYJHh/83SN/QSjN646tEf/I2jTGF+1za89i6vtLa+wUKOQ4gamuRnYi+7AJA=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@pinecone-experience/messages/MAL-2026-17631.json"