🛡️ MAL-2026-12402 — new-native-tools-linux-x64-gnu
Description
Malicious code in new-native-tools-linux-x64-gnu (npm)
Source: amazon-inspector
The package ships a single ~10 MB Rust-compiled Linux x86_64 N-API native module (tools.linux-x64-gnu.node) referenced by main, with a two-line README that describes it only as a platform binary and no source. The binary embeds Chromium browser-secret extraction primitives — the Chromium cookies table schema (host_key, top_frame_site_key, has_cross_site_ancestor, unique-index DDL) and the Chrome Login Data password-store fingerprint (Found login for), plus SQLite/SQLCipher symbols including SQLITE_AUTH_USER — the components required to read Chrome/Chromium Cookies and Login Data stores on the host that loads the module. The same binary embeds a full HTTPS client (hyper, ureq, TLS 1.2/1.3 handshake constants, HTTP/2 framing) with proxy-environment awareness (HTTPS_PROXY, ALL_PROXY) and host-fingerprinting reads (/etc/lsb-release, /dev/disk/by-id/, bogomips per cpu, CPU implementer, network_adapters, gethostname) — the transport layer and host-identification data for exfiltration. The version tag 3.1.40-chrom-553-fix-undeletable-import-cookies-355-1784226602 labels the actual capability (Chromium cookie import) while the package name and README hide it behind a generic "native-tools" cover story. The exfil destination is assembled at runtime rather than appearing as a static literal, consistent with obfuscation of C2. Loading this module via require() exposes the installer's browser cookies and saved passwords to an attacker-controlled destination.
Affected software
MAL-2026-12402 is recorded against 1 package.
- new-native-tools-linux-x64-gnu
Timeline and source
Published on 5 August 2026 and last revised on 6 August 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| new-native-tools-linux-x64-gnu | — | — |
References
More MAL 2026 advisories
Browse all of MAL 2026 in the advisory index.
Free Vulnerability Check
Is your site affected by MAL-2026-12402?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against MAL-2026-12402 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.