MAL-2026-11064
Dashboard / Malicious Package / MAL-2026-11064
MAL-2026-11064
Summary: Malicious code in page-navigation (npm)
Details: Source: amazon-inspector (99958415864bd2ddd266b99c59cdc35841e7efd9eff38481d69f4e740badd958) On npm install, the package's preinstall hook runs index.js, which collects the installer's hostname, OS username, home directory, DNS server list, __dirname, package.json contents, and the contents of /etc/passwd and /etc/hosts, and HTTPS-POSTs the collected data to a hardcoded Burp Collaborator subdomain at 0ef84h7vro1unpywu477drayyp4gs8gx.oastify.com. The behavior fires automatically on default install with no user interaction and targets installer-side system files and identifiers rather than the package's declared purpose. Source: ossf-package-analysis (c65bfe970c4520a6ac5c7e51efa638985191d6e01ee4cf3db97d270cff115d37) The OpenSSF Package Analysis project identified 'page-navigation' @ 1.0.1 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity.
Affected packages
Package
Name: page-navigation
Purl: pkg:npm/page-navigation
Affected ranges
Type: N/A
Events:
