MAL-2026-10084
Dashboard / Malicious Package / MAL-2026-10084
MAL-2026-10084
Summary: Malicious code in conversionvaluemanager (npm)
Details: Source: amazon-inspector (21445a74cc1c4d33c89f1a7d8c357c79d5adb11cda135c813676b23c875418e9) On npm install, postinstall.js automatically runs and gathers installer-identifying data (os.hostname(), os.userInfo(), os.platform(), cwd, Node version, timestamp), then sends it as query-string parameters via plain-HTTP GET to a Burp Collaborator subdomain at aq4v2egelzh9n07h3l9d2b5mvd14pvdk.oastify.com/adjust-dep-confusion. The package.json description self-identifies as a dependency-confusion proof-of-concept ("PoC - Dependency Confusion - Bug Bounty by ha4x0r"), and the package name targets an internal/private package name. Any organization whose build misresolves to this public package leaks host, user, and environment identifiers to the third-party Collaborator endpoint on install. PoC/bug-bounty framing does not change the installer-side impact: the beacon fires on every install.
References: https://www.npmjs.com/package/conversionvaluemanager/v/3.0.0, https://github.com/advisories/GHSA-c8w9-r7mv-28q4
Affected packages
Package
Name: conversionvaluemanager
Purl: pkg:npm/conversionvaluemanager
Affected ranges
Type: N/A
Events:
