MAL-2026-10739

    Dashboard / Malicious Package / MAL-2026-10739

    MAL-2026-10739

    Published: 16 Jul 2026Last Modified: 16 Jul 2026

    Summary: Malicious code in mw-server-util (npm)

    Details: Source: amazon-inspector (1401412848e55e1515db44b1f513ad6e39628f06c24c3b057a08448c9e8ee44c) mw-server-util 2.0.1 ships a postinstall hook that runs mw.js, which reads os.hostname() and os.userInfo() and issues an HTTPS GET to a hardcoded Burp Collaborator subdomain gdx35zc4m7hymba6asotmwhd349vxlla.oastify.com, transmitting the installer's hostname, username, package name, and a timestamp on `npm install`. The destination is an attacker-controlled OAST callback typical of dependency-confusion beacons; the fetch fires automatically as a lifecycle side effect with no relation to any documented package purpose.

    Affected packages

    Package

    Name: mw-server-util

    Purl: pkg:npm/mw-server-util

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    2.0.1
    2.0.0
    MAL-2026-10739 | CVE-DB