MAL-2026-10683

    Dashboard / Malicious Package / MAL-2026-10683

    MAL-2026-10683

    Published: 15 Jul 2026Last Modified: 15 Jul 2026

    Summary: Malicious code in formatters.ts (npm)

    Details: Source: amazon-inspector (21827129edc8dbde114c615df656d5a234d1fbcfa5b9f63d5286d781253e8f2b) The package declares a preinstall hook that runs index.js on npm install. index.js collects host and identity reconnaissance — os.hostname(), os.platform(), os.arch(), os.homedir(), os.userInfo() (username, uid, gid, shell), OS release, memory, CPU count, and the output of the `whoami`, `id`, and `pwd` shell commands — and POSTs the JSON payload to a hardcoded Burp Collaborator subdomain at https://y43nklho48nnebq8qpmw3ngha8gz4pse.oastify.com/detox56. The package name resembles a legitimate formatter/TypeScript module and ships with empty description/author metadata, consistent with a dependency-confusion typosquat lure whose sole purpose is the install-time beacon.

    Affected packages

    Package

    Name: formatters.ts

    Purl: pkg:npm/formatters.ts

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    14.2.1
    MAL-2026-10683 | CVE-DB