MAL-2026-10183

    Dashboard / Malicious Package / MAL-2026-10183

    MAL-2026-10183

    Published: 10 Jul 2026Last Modified: 1 Sept 2026Aliases: 
    GHSA-rc5q-c5vp-6g46

    Summary: Malicious code in fkext-browser-min (npm)

    Details: Source: amazon-inspector (1e56088bc1216133ce76ad6026b73c2fd6977f9c64ec1c2ab38234dc90403b2c) The package runs vishu.js as a preinstall lifecycle hook on `npm install`. That script fetches the machine's public IP from api.ipify.org, collects os.hostname() and GitHub Actions / CI environment variables (GITHUB_*), and transmits them as query parameters to a hardcoded webhook.site collector URL over HTTPS. It additionally performs a DNS lookup of a subdomain of the form `ping-<hostname>.<collaborator>.oastify.com`, providing an out-of-band exfiltration channel (Burp Collaborator style) that bypasses HTTP egress filters. There is no legitimate functionality shipped alongside this — the package's only install-time effect is host reconnaissance and beacon-out to attacker-controlled sinks. This is a dependency-confusion / bug-bounty-style beacon against installer/CI environments.

    Affected packages

    Package

    Name: fkext-browser-min

    Purl: pkg:npm/fkext-browser-min

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.14
    MAL-2026-10183 | CVE-DB