MAL-2026-10128

    Dashboard / Malicious Package / MAL-2026-10128

    MAL-2026-10128

    Published: 10 Jul 2026Last Modified: 10 Jul 2026

    Summary: Malicious code in ohcm-culture-formatting (npm)

    Details: Source: amazon-inspector (5679f4434881406ce5af055e04a3ab7403158df3404c928a7fbc67596d0e9631) [email protected] declares a preinstall hook (`"preinstall": "node index.js"`) that auto-executes on `npm install`. index.js uses `child_process.exec` to run a shell pipeline that reads `/etc/passwd`, `/etc/hosts`, `/etc/shadow`, and `id` output, base64-encodes the concatenation, and POSTs it via curl to `http://d98fu4tmls2g936th9qgfxje1qj9g91a6.oast.fun/ohcm-culture-formatting/$(whoami)/$(hostname)/`, embedding the installer's username and hostname in the URL path and the file contents in the User-Agent header. The destination is an Interactsh/OAST out-of-band interaction collector. The package name mimics an internal ADP/Lifion (`ohcm-*`) namespace and the description string is `Lifion host`, consistent with a dependency-confusion payload targeting that internal namespace.

    Affected packages

    Package

    Name: ohcm-culture-formatting

    Purl: pkg:npm/ohcm-culture-formatting

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    5.0.0