MAL-2026-11093

    Dashboard / Malicious Package / MAL-2026-11093

    MAL-2026-11093

    Published: 27 Jul 2026Last Modified: 7 Aug 2026

    Summary: Malicious code in @heartlandone-private/fontawesome-pro (npm)

    Details: Source: amazon-inspector (5dc8f9f53c05ecc2642ce82c3841e046025662c206f002b4c6da11ff0cbc763d) The package's postinstall lifecycle hook runs `node index.js`, which issues an HTTPS GET to a hardcoded Burp Collaborator subdomain at `e0fumpwx24ddfmenzmg0izs2atgk4es3.oastify.com/dependency-confusion` with a User-Agent identifying it as a dependency-confusion probe. On any `npm install` that resolves this scoped name, the request fires automatically and discloses installer identity (source IP, DNS resolver, timing, request metadata) to a third-party out-of-band interaction server controlled by whoever provisioned the Collaborator instance. The package name uses a private-scope pattern (`@heartlandone-private/fontawesome-pro`) that mimics an internal artifact, consistent with a dependency-confusion attempt aimed at organizations whose internal `@heartlandone-private` scope is not reserved on the public registry. Whether the operator's intent is authorized red-team testing or opportunistic exploitation, any consumer whose install pipeline resolves this public package receives install-time code execution and outbound network signalling to an attacker-controlled callback. Source: ossf-package-analysis (b5bd52805195c9e3575760b3eaf605a2b9cb0fcbdde2311b7075d2d8095c4900) The OpenSSF Package Analysis project identified '@heartlandone-private/fontawesome-pro' @ 6.3.3 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity.

    Affected packages

    Package

    Name: @heartlandone-private/fontawesome-pro

    Purl: pkg:npm/%40heartlandone-private/fontawesome-pro

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    6.3.3
    6.3.6
    6.3.2