MAL-2026-11119
Dashboard / Malicious Package / MAL-2026-11119
MAL-2026-11119
Summary: Malicious code in json-to-table-util (npm)
Details: Source: amazon-inspector (2317bf7f973ca611fdd2215509ae94c302f868ae9fb5c5f00de0b6bd13fe3bc4) postinstall.js runs automatically on `npm install` and executes a shell pipeline via child_process.exec that collects hostname, user, working directory, uname, container/cgroup indicators, process tree, network info (/etc/resolv.conf, IPs), GitHub Actions CI variables (GITHUB_REPOSITORY, GITHUB_ACTOR, GITHUB_RUN_ID, RUNNER_NAME), and the entire process environment via `env` (filtering only npm_* noise). It also probes AWS IMDS at 169.254.169.254 and Tencent Cloud metadata at metadata.tencentyun.com to fingerprint cloud infrastructure. The aggregated output is base64-encoded and sent over plain HTTP via curl GET to the hardcoded Burp Collaborator subdomain pzs5w7ntzhsnepwk564lyfdci3oucl0a.oastify.com/z?d=<base64>. On CI runners this captures any secrets exported to the environment (cloud keys, GITHUB_TOKEN, tokens injected into the job). Source: ossf-package-analysis (63ee08885a126855fbc96dbbb6f8c4ef903d9dc8f2cb02fe0fa178a7db1ed904) The OpenSSF Package Analysis project identified 'json-to-table-util' @ 1.0.0 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity. - The package executes one or more commands associated with malicious behavior.
Affected packages
Package
Name: json-to-table-util
Purl: pkg:npm/json-to-table-util
Affected ranges
Type: N/A
Events:
