MAL-2026-11055

    Dashboard / Malicious Package / MAL-2026-11055

    MAL-2026-11055

    Published: 25 Jul 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in fundraiserservicepp (npm)

    Details: Source: amazon-inspector (6356b654b692d4c1222f3dc31dcfad683a6e193a41484d3c617c7c8d52db2313) On npm install, the package's preinstall lifecycle executes index.js which collects os.hostname(), os.platform(), and os.arch() and POSTs them as JSON over HTTPS to the hardcoded subdomain rpke7za0zz1pwj9fz5058j0y5pbgz82wr.oastify.com — a Burp Collaborator out-of-band collector. The package provides no advertised functionality beyond this beacon and matches the dependency-confusion probe shape, with installer host identifiers leaving the machine automatically to a third-party OOB endpoint the installer did not opt into. Source: ossf-package-analysis (cefb4588a67439c112176df4b9af71d40a1e2a12e0bf81ef200affa79e0cb0e0) The OpenSSF Package Analysis project identified 'fundraiserservicepp' @ 1.5.0 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity.

    Affected packages

    Package

    Name: fundraiserservicepp

    Purl: pkg:npm/fundraiserservicepp

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.5.0
    MAL-2026-11055 | CVE-DB