MAL-2025-6695

    Dashboard / Malicious Package / MAL-2025-6695

    MAL-2025-6695

    Published: 1 Aug 2025Last Modified: 13 Jul 2026

    Summary: Malicious code in amdocs-core-package (npm)

    Details: The package communicates with a domain associated with malicious activity. Source: amazon-inspector (1e196068c171b8528ec4f1f0db852ef32a7b530ecce14d79696a21c4f685c2c6) The package declares a preinstall hook that runs index.js on npm install. index.js requires https and os, reads os.hostname(), and issues an https.request POST to a hardcoded *.oastify.com Burp Collaborator subdomain, additionally embedding the hostname into the DNS label of that subdomain for out-of-band capture. Package metadata is placeholder (empty description and author, version 11.11.11, name shaped like an internal 'amdocs' scope), consistent with a dependency-confusion payload targeting an internal namespace. Installing the package causes the installer's host identifier to leave the machine to an attacker-controlled collaborator domain.

    Affected packages

    Package

    Name: amdocs-core-package

    Purl: pkg:npm/amdocs-core-package

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 1.0.0
    Fixed -None

    Affected versions

    11.11.11
    MAL-2025-6695 | CVE-DB