MAL-2026-11045

    Dashboard / Malicious Package / MAL-2026-11045

    MAL-2026-11045

    Published: 24 Jul 2026Last Modified: 4 Aug 2026

    Summary: Malicious code in subapp-pkg-util (npm)

    Details: Source: amazon-inspector (ae51b43e9a5110ec02eb9aa1cbf03837b2a560f4b6c8168b1c2d675802a113ae) package.json declares a postinstall hook that runs index.js on npm install. index.js collects host identifiers (os.hostname(), os.userInfo(), os.platform(), OS release) and enriches them with public IP (via ipify) and geo/ISP (via ipapi.co), then POSTs the JSON payload to a hardcoded Burp Collaborator subdomain at https://dq7q2vt6l79ouvgyzavan3w2rtxkp8gw5.oastify.com/callback. The package self-describes as a dependency-confusion takeover PoC; the beacon fires automatically on install without user interaction. Source: ossf-package-analysis (9ec05191ebd2f02dcf912c49fc5d345c3b9201fb691a11a0142fec91cc6d42d4) The OpenSSF Package Analysis project identified 'subapp-pkg-util' @ 99.0.1 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity.

    Affected packages

    Package

    Name: subapp-pkg-util

    Purl: pkg:npm/subapp-pkg-util

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    99.0.1