MAL-2024-2031

    Dashboard / Malicious Package / MAL-2024-2031

    MAL-2024-2031

    Published: 25 Jun 2024Last Modified: 1 Sept 2026Aliases: 
    GHSA-9wxp-r2hc-p64q

    Summary: Malicious code in crosswalker (npm)

    Details: Source: amazon-inspector (b352c9c53fc71d511dae5d0fd8acc4462286092822d70e37dd413593f12bf0d3) package.json declares `preinstall: node index.js`, causing index.js to run automatically on `npm install`. The script collects hostname, platform, arch, homedir, username, uid/gid, shell, OS info, cwd, and the output of `whoami` and `id`, then POSTs the JSON payload to a hardcoded URL at `https://kbz9yyzq2mtljdwwf6r0tpzlfcl39txi.oastify.com/detox56`. The destination is a Burp Collaborator subdomain — out-of-band infrastructure used to confirm exfiltration / RCE during dependency-confusion reconnaissance. Installer host and user identifiers leave the machine without consent on every install.

    Affected packages

    Package

    Name: crosswalker

    Purl: pkg:npm/crosswalker

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.1
    1.0.0