MAL-2026-11065
Dashboard / Malicious Package / MAL-2026-11065
MAL-2026-11065
Summary: Malicious code in swiper_angular (npm)
Details: Source: amazon-inspector (35a523a0f2bb0df423657f50e42be71ae87d3071b859e1f4eb88a90709ba0ca5) Package name typosquats swiper/swiper-angular at implausible version 5.9999.1. The preinstall.js script runs at install time and collects installer host identity and network context — os.hostname(), os.userInfo() username, current working directory, package name, git remote domain, /etc/resolv.conf search domain, /etc/hosts and /etc/hostname content grepped for 'tbi|beez|tbibank', egress IP via `ip route get 1.1.1.1` and `curl -s ifconfig.me`, and environment variable names filtered against the same organization tokens. The collected fields are concatenated into a query string and sent via https.get to the hardcoded Interactsh subdomain rmknhtfmmidejheotogony3qpqrk75wdz.oast.fun/cb2. Behavior fires automatically on npm install with no consent prompt and targets a specific organization (tbibank) regardless of the self-applied 'security research' label. Source: ossf-package-analysis (474db4780bfc49ff2146966bdd508c123baf4d39c636e27aaba1996a0016d8f6) The OpenSSF Package Analysis project identified 'swiper_angular' @ 5.9999.0 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity.
References: https://www.npmjs.com/package/swiper_angular/v/5.9999.0, https://www.npmjs.com/package/swiper_angular/v/5.9999.1
Affected packages
Package
Name: swiper_angular
Purl: pkg:npm/swiper_angular
Affected ranges
Type: N/A
Events:
