MAL-2026-10734

    Dashboard / Malicious Package / MAL-2026-10734

    MAL-2026-10734

    Published: 16 Jul 2026Last Modified: 16 Jul 2026

    Summary: Malicious code in infrastructure-common (npm)

    Details: Source: amazon-inspector (d64169ae87d8d9eaad199be028a70610f025f61e0c947838c05c24a1dd4d5578) package.json declares a preinstall lifecycle script that runs `node -e` to issue an HTTP GET to a Burp Collaborator subdomain at w635fyvrqkfmh9wc9uw8444cp3vujl7a.oastify.com when `npm install` runs. The callback confirms code execution on the installer's host and leaks the installer's public IP and DNS resolver to a third-party listener. The package name `infrastructure-common` combined with an implausibly high `99.9.9` version is the canonical dependency-confusion shape, in which a public package is registered to shadow an internal name at install-time resolution.

    Affected packages

    Package

    Name: infrastructure-common

    Purl: pkg:npm/infrastructure-common

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    99.9.9
    MAL-2026-10734 | CVE-DB