MAL-2026-11152
Dashboard / Malicious Package / MAL-2026-11152
MAL-2026-11152
Summary: Malicious code in tidal-embed-player (npm)
Details: Source: amazon-inspector (005d40bc86aa5e012bfb9a0cd23cf5de5c4d93b1f65880b2273b8708891fa7e5) package.json declares a preinstall hook that runs index.js on `npm install`. index.js collects host identifiers (os.hostname(), os.userInfo().username, homedir, DNS servers, cwd), reads the package.json, and reads /etc/passwd and /etc/hosts from the installer host, then POSTs the combined payload over HTTPS to 1rtlwocct2ruj1kc2njqbw96wx2qqhe6.oastify.com — a Burp Collaborator subdomain used to receive out-of-band callbacks. The package name suggests a Tidal media embed player but the shipped code performs only host reconnaissance and exfiltration, with no player functionality. Source: ghsa-malware (2431f85c58e75a787b5d6ee7f9bc2d2c86401aed86c9ce42605bcd2387124ca7) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
References: https://www.npmjs.com/package/tidal-embed-player/v/1.0.1, https://github.com/advisories/GHSA-7w7p-cq73-h3p4, https://www.npmjs.com/package/tidal-embed-player/v/1.0.2
Affected packages
Package
Name: tidal-embed-player
Purl: pkg:npm/tidal-embed-player
Affected ranges
Type: SEMVER
Events:
