MAL-2026-11152

    Dashboard / Malicious Package / MAL-2026-11152

    MAL-2026-11152

    Published: 28 Jul 2026Last Modified: 9 Sept 2026Aliases: 
    GHSA-7w7p-cq73-h3p4

    Summary: Malicious code in tidal-embed-player (npm)

    Details: Source: amazon-inspector (005d40bc86aa5e012bfb9a0cd23cf5de5c4d93b1f65880b2273b8708891fa7e5) package.json declares a preinstall hook that runs index.js on `npm install`. index.js collects host identifiers (os.hostname(), os.userInfo().username, homedir, DNS servers, cwd), reads the package.json, and reads /etc/passwd and /etc/hosts from the installer host, then POSTs the combined payload over HTTPS to 1rtlwocct2ruj1kc2njqbw96wx2qqhe6.oastify.com — a Burp Collaborator subdomain used to receive out-of-band callbacks. The package name suggests a Tidal media embed player but the shipped code performs only host reconnaissance and exfiltration, with no player functionality. Source: ghsa-malware (2431f85c58e75a787b5d6ee7f9bc2d2c86401aed86c9ce42605bcd2387124ca7) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

    Affected packages

    Package

    Name: tidal-embed-player

    Purl: pkg:npm/tidal-embed-player

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -None

    Affected versions

    1.0.1
    1.0.2
    MAL-2026-11152 | CVE-DB