MAL-2026-10212
Dashboard / Malicious Package / MAL-2026-10212
MAL-2026-10212
Summary: Malicious code in vuln-package (npm)
Details: Source: amazon-inspector (a8bd105bf3b12062f312b41f2a1eead5e8481f8d3749fc78bc79ed8675c11394) On npm install, the package's preinstall script triggers a DNS lookup to a unique subdomain of oast.fun (fabekzbnjtufpffkzzmvjvi5eafhny3ok.oast.fun), an out-of-band interaction service, confirming code execution on the installer's machine to a third-party collector. A sibling file indexCopy.js collects host identifiers (os.userInfo().username, os.hostname(), process.cwd(), and process.env references) and issues an https.request POST to a hardcoded webhook.site endpoint (https://webhook.site/cde465c1-3853-40ea-880c-fdca6fe508cc). The combination of an OOB DNS beacon at install time and a staged HTTPS exfiltration payload targeting installer host identifiers is characteristic of a supply-chain reconnaissance/exfiltration attack rather than any legitimate package behavior.
References: https://www.npmjs.com/package/vuln-package/v/99.9.11, https://www.npmjs.com/package/vuln-package/v/99.9.14, https://www.npmjs.com/package/vuln-package/v/99.9.9, https://www.npmjs.com/package/vuln-package/v/99.9.10
Affected packages
Package
Name: vuln-package
Purl: pkg:npm/vuln-package
Affected ranges
Type: N/A
Events:
