MAL-2026-10636

    Dashboard / Malicious Package / MAL-2026-10636

    MAL-2026-10636

    Published: 15 Jul 2026Last Modified: 15 Jul 2026

    Summary: Malicious code in leviosa86-test (npm)

    Details: Source: amazon-inspector (46b0bed6337ffe527af2615fed8ae1ecbb449f6a6cb00afa6381f7811ec88956) [email protected] ships src/poc/index.js which uses child_process.exec to run a shell pipeline that collects host reconnaissance data (hostname, current working directory, whoami, a package identifier) and the public egress IP fetched from https://ifconfig.me, concatenates the values, and exfiltrates them via nslookup as a subdomain label of d9bd62bu6g119svvav70o3p9tymtrxkoj.oast.site — an Interactsh (project-discovery) out-of-band callback domain. The generic package name combined with the anomalous 4.999.0 version bump is the canonical dependency-confusion research/attack shape, where a high version number is published to a public registry to override a private internal package and cause the recon payload to fire in the victim's build.

    Affected packages

    Package

    Name: leviosa86-test

    Purl: pkg:npm/leviosa86-test

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    4.999.0