MAL-2026-10632

    Dashboard / Malicious Package / MAL-2026-10632

    MAL-2026-10632

    Published: 14 Jul 2026Last Modified: 15 Jul 2026

    Summary: Malicious code in cppt-common (npm)

    Details: Source: amazon-inspector (484688d5963a9246f4fe7a2b5c1c7ebe6bba135a2a5df66b3ab57f44978407b2) [email protected] declares a preinstall hook ("preinstall": "node index.js") that runs automatically on npm install. index.js collects host and user identifiers — os.hostname(), os.userInfo(), the output of `whoami` and `id` via child_process.exec, platform/arch/memory, cwd, homedir, and shell — and POSTs the collected JSON to a hardcoded endpoint at https://mj9yg25wm8m4vnkrrok8lwcogfm6awyl.oastify.com/detox56. The oastify.com host is a Burp Collaborator out-of-band callback domain used for exfiltration. The package has empty description and author fields and provides no advertised functionality; its only install-time effect is the reconnaissance beacon.

    Affected packages

    Package

    Name: cppt-common

    Purl: pkg:npm/cppt-common

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    13.1.1
    MAL-2026-10632 | CVE-DB