Vulnerability MAL-2026-17710
Summary
Malicious code in pxnpm (npm)
Details
pxnpm 7.0.0-beta.6, 7.0.0-beta.8 and 7.0.0 (published 2026-10-06 by user nfjbill) are a 10-file, 16 KB launcher for a native executable that is not contained in the package. The postinstall script (bin/install.cjs) calls ensureNative() in dist/download.cjs, which downloads a 17-21 MB Brotli archive for the current platform from a non-npm host, https://registry-pxnpm.rdc.nfjbill.ren:20021/__static/srv/downloads/pxnpm//-.br, decompresses it into a 52-72 MB executable under ~/.cache/pxnpm/native///, sets mode 0755, and the launcher (dist/launcher.cjs line 54) later runs it with child_process.spawn. The manifest (dist/native-manifest.json) sets networkPolicy 'fixed', so the environment variables that would let a user supply a reviewed binary or a different download location are ignored; the archive and the executable are verified only against hashes shipped in the same package.
When run, dist/launcher.cjs prepare() deletes every registry and proxy setting from the user's environment (npm_config_registry, scoped registries, http(s)_proxy, no_proxy and the pnpm/pxnpm equivalents), rejects --registry and --proxy flags, and forces PXNPM_CONFIG_REGISTRY to https://registry-pxnpm.rdc.nfjbill.ren:20021/ and PXNPM_CONFIG_PROXY, HTTPS_PROXY and HTTP_PROXY to an authenticated proxy URL on the same host, port 20022 (a gost proxy), that is embedded in the file as a base64 string with the comment 'Filled only in the release staging directory; never store credentials in Git'. All package traffic of a user of this public package is therefore routed through the author's host, which can observe and alter it.
Nothing in the package name, the one-line README or the install output discloses that an executable will be fetched from a private host or that registry and proxy settings will be replaced. The JavaScript itself contains no data collection and no obfuscation beyond the base64 string. At the time of this report the download URL returns a 430-byte npm registry JSON document instead of the archive, so installation from outside the author's network fails at the checksum step and the executable could not be examined; its behavior is unknown. The same host is the hard-coded endpoint of yakuza0 2.23.40 by the same author (MAL-2026-13605).
Trigger: on install (postinstall) and on every run. Type: silent install-time download and execution of an unreviewable binary from a private host, with hijacking of registry and proxy settings.