MAL-2026-11065

    Dashboard / Malicious Package / MAL-2026-11065

    MAL-2026-11065

    Published: 25 Jul 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in swiper_angular (npm)

    Details: Source: amazon-inspector (35a523a0f2bb0df423657f50e42be71ae87d3071b859e1f4eb88a90709ba0ca5) Package name typosquats swiper/swiper-angular at implausible version 5.9999.1. The preinstall.js script runs at install time and collects installer host identity and network context — os.hostname(), os.userInfo() username, current working directory, package name, git remote domain, /etc/resolv.conf search domain, /etc/hosts and /etc/hostname content grepped for 'tbi|beez|tbibank', egress IP via `ip route get 1.1.1.1` and `curl -s ifconfig.me`, and environment variable names filtered against the same organization tokens. The collected fields are concatenated into a query string and sent via https.get to the hardcoded Interactsh subdomain rmknhtfmmidejheotogony3qpqrk75wdz.oast.fun/cb2. Behavior fires automatically on npm install with no consent prompt and targets a specific organization (tbibank) regardless of the self-applied 'security research' label. Source: ossf-package-analysis (474db4780bfc49ff2146966bdd508c123baf4d39c636e27aaba1996a0016d8f6) The OpenSSF Package Analysis project identified 'swiper_angular' @ 5.9999.0 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity.

    Affected packages

    Package

    Name: swiper_angular

    Purl: pkg:npm/swiper_angular

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    5.9999.0
    5.9999.1
    MAL-2026-11065 | CVE-DB