MAL-2026-11170

    Dashboard / Malicious Package / MAL-2026-11170

    MAL-2026-11170

    Published: 29 Jul 2026Last Modified: 14 Aug 2026

    Summary: Malicious code in @finxsecdemo/utils (npm)

    Details: Source: amazon-inspector (be118b4cf0acab2c331cc37f68a19bdbdf2ac8423ef984a1cac5c9f4d21c1e7e) The postinstall.js lifecycle script unconditionally issues an HTTPS GET and a DNS resolution against a hardcoded interact.sh/OAST subdomain (llhvrrffsffmousfvteqie2heq3c7rl55.oast.fun) on every install, reading os.hostname(), os.userInfo(), and process.env in the surrounding code. The beacon fires on `npm install` and reports the installer's source IP and DNS resolver IP to whoever owns the OAST token, giving them an enumeration list of hosts on which the package landed. The package's own `main` returns a formatCurrency string containing '[DEPENDENCY-CONFUSION-POC: this ran from the PUBLIC npm registry, not @finxsecdemo private packages]', which corrupts any consumer that displays formatted currency. Console framing as a 'dependency confusion PoC' is author-controlled labeling; the network callback and output corruption occur regardless. Source: ossf-package-analysis (f6ca8fa85d211056af32639b18f95f13c362b2764d85c812e6741d6747abf94d) The OpenSSF Package Analysis project identified '@finxsecdemo/utils' @ 1.0.2 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity.

    Affected packages

    Package

    Name: @finxsecdemo/utils

    Purl: pkg:npm/%40finxsecdemo/utils

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.2
    1.0.3
    MAL-2026-11170 | CVE-DB