MAL-2026-11064

    Dashboard / Malicious Package / MAL-2026-11064

    MAL-2026-11064

    Published: 25 Jul 2026Last Modified: 4 Aug 2026

    Summary: Malicious code in page-navigation (npm)

    Details: Source: amazon-inspector (99958415864bd2ddd266b99c59cdc35841e7efd9eff38481d69f4e740badd958) On npm install, the package's preinstall hook runs index.js, which collects the installer's hostname, OS username, home directory, DNS server list, __dirname, package.json contents, and the contents of /etc/passwd and /etc/hosts, and HTTPS-POSTs the collected data to a hardcoded Burp Collaborator subdomain at 0ef84h7vro1unpywu477drayyp4gs8gx.oastify.com. The behavior fires automatically on default install with no user interaction and targets installer-side system files and identifiers rather than the package's declared purpose. Source: ossf-package-analysis (c65bfe970c4520a6ac5c7e51efa638985191d6e01ee4cf3db97d270cff115d37) The OpenSSF Package Analysis project identified 'page-navigation' @ 1.0.1 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity.

    Affected packages

    Package

    Name: page-navigation

    Purl: pkg:npm/page-navigation

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.1