MAL-2026-11045
Dashboard / Malicious Package / MAL-2026-11045
MAL-2026-11045
Summary: Malicious code in subapp-pkg-util (npm)
Details: Source: amazon-inspector (ae51b43e9a5110ec02eb9aa1cbf03837b2a560f4b6c8168b1c2d675802a113ae) package.json declares a postinstall hook that runs index.js on npm install. index.js collects host identifiers (os.hostname(), os.userInfo(), os.platform(), OS release) and enriches them with public IP (via ipify) and geo/ISP (via ipapi.co), then POSTs the JSON payload to a hardcoded Burp Collaborator subdomain at https://dq7q2vt6l79ouvgyzavan3w2rtxkp8gw5.oastify.com/callback. The package self-describes as a dependency-confusion takeover PoC; the beacon fires automatically on install without user interaction. Source: ossf-package-analysis (9ec05191ebd2f02dcf912c49fc5d345c3b9201fb691a11a0142fec91cc6d42d4) The OpenSSF Package Analysis project identified 'subapp-pkg-util' @ 99.0.1 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity.
Affected packages
Package
Name: subapp-pkg-util
Purl: pkg:npm/subapp-pkg-util
Affected ranges
Type: N/A
Events:
