MAL-2026-11170
Dashboard / Malicious Package / MAL-2026-11170
MAL-2026-11170
Summary: Malicious code in @finxsecdemo/utils (npm)
Details: Source: amazon-inspector (be118b4cf0acab2c331cc37f68a19bdbdf2ac8423ef984a1cac5c9f4d21c1e7e) The postinstall.js lifecycle script unconditionally issues an HTTPS GET and a DNS resolution against a hardcoded interact.sh/OAST subdomain (llhvrrffsffmousfvteqie2heq3c7rl55.oast.fun) on every install, reading os.hostname(), os.userInfo(), and process.env in the surrounding code. The beacon fires on `npm install` and reports the installer's source IP and DNS resolver IP to whoever owns the OAST token, giving them an enumeration list of hosts on which the package landed. The package's own `main` returns a formatCurrency string containing '[DEPENDENCY-CONFUSION-POC: this ran from the PUBLIC npm registry, not @finxsecdemo private packages]', which corrupts any consumer that displays formatted currency. Console framing as a 'dependency confusion PoC' is author-controlled labeling; the network callback and output corruption occur regardless. Source: ossf-package-analysis (f6ca8fa85d211056af32639b18f95f13c362b2764d85c812e6741d6747abf94d) The OpenSSF Package Analysis project identified '@finxsecdemo/utils' @ 1.0.2 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity.
References: https://www.npmjs.com/package/@finxsecdemo/utils/v/1.0.2, https://www.npmjs.com/package/@finxsecdemo/utils/v/1.0.3
Affected packages
Package
Name: @finxsecdemo/utils
Purl: pkg:npm/%40finxsecdemo/utils
Affected ranges
Type: N/A
Events:
