MAL-2026-10458

    Dashboard / Malicious Package / MAL-2026-10458

    MAL-2026-10458

    Published: 13 Jul 2026Last Modified: 13 Jul 2026

    Summary: Malicious code in compliancepolicyserv (npm)

    Details: Source: amazon-inspector (a9f18c11413e208ef48e083af8a065b36134c2b37b5fd1474a5701a986a659d8) [email protected] registers index.js as both scripts.install and main. On npm install and on require, index.js loads lib/core.js, which reads os.userInfo().username, os.hostname(), and process.cwd(), concatenates them with a 'paypal' prefix, a timestamp, and the domain oob.sl4x0.xyz, and issues a dns.resolve4 query against the resulting subdomain, beaconing installer identifiers over DNS to an author-controlled domain. The destination host and the names of the os/dns/process APIs and their methods (userInfo, hostname, cwd, resolve4) are reconstructed at runtime from char-code arrays in lib/b02e30.js and lib/6ad264.js, hiding the exfil endpoint and sensitive API references from static inspection. The package name resembles a compliance-policy service but the shipped code performs no such function; the sole install/import-time effect is the DNS beacon.

    Affected packages

    Package

    Name: compliancepolicyserv

    Purl: pkg:npm/compliancepolicyserv

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    9.9.11