MAL-2026-10179

    Dashboard / Malicious Package / MAL-2026-10179

    MAL-2026-10179

    Published: 10 Jul 2026Last Modified: 1 Sept 2026Aliases: 
    GHSA-8rcq-736v-r8j8

    Summary: Malicious code in @uwr/colors (npm)

    Details: Source: amazon-inspector (91240d8fb55b7ed4730a41f3a334c633bf1a03afb649fd473cad0c0a25312847) The package's postinstall script reads the installer's machine hostname via os.hostname() and performs a DNS lookup of `<hostname>.0ab1mctv5xigbskwtfusp77dj4pvdx1m.oastify.com`, leaking the hostname to a Burp Suite Collaborator subdomain at `npm install` time without consent. oastify.com is the Burp Collaborator service, commonly used by attackers as an out-of-band data-exfiltration channel. The package's advertised functionality is a trivial 5-entry frozen color constants map under the unscoped-looking @uwr scope ("colors for the unified workflow runtime") with an empty author field, consistent with a dependency-confusion / reconnaissance probe staged against an internal namespace rather than a legitimate library.

    Affected packages

    Package

    Name: @uwr/colors

    Purl: pkg:npm/%40uwr/colors

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.3.6
    MAL-2026-10179 | CVE-DB