MAL-2026-11147

    Dashboard / Malicious Package / MAL-2026-11147

    MAL-2026-11147

    Published: 28 Jul 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in simple-probe-utils (npm)

    Details: Source: amazon-inspector (0457a026ab28fbb641d11e4e9ac9d60d026fd77210972f72e6ac931b4b06c59c) On npm install, postinstall.js executes shell commands that query cloud instance metadata services (AWS IMDS at 169.254.169.254, plus Tencent, Aliyun, GCP, and Azure endpoints) and extracts the AWS IAM role's temporary security credentials. The captured IAM credentials, hostname, and username are appended as query parameters to an HTTP request to the hardcoded out-of-band host pzs5w7ntzhsnepwk564lyfdci3oucl0a.oastify.com (a Burp Collaborator-style domain). The package.json describes the module as a lightweight string formatting helper; the shipped code contains only the credential-harvesting postinstall, with no string-utility functionality present.

    Affected packages

    Package

    Name: simple-probe-utils

    Purl: pkg:npm/simple-probe-utils

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.1
    1.0.0
    MAL-2026-11147 | CVE-DB