MAL-2026-11430

    Dashboard / Malicious Package / MAL-2026-11430

    MAL-2026-11430

    Published: 2 Aug 2026Last Modified: 4 Aug 2026

    Summary: Malicious code in list-issue-predecessor-dependencies-block (npm)

    Details: Source: amazon-inspector (bbd4d4e3aa51ec1a7ebc0a0d4f728698503432546f139f67998849f8fff9b614) npm package [email protected] auto-executes index.js from three lifecycle hooks (preinstall, install, postinstall) on npm install. The script collects installer identity and environment reconnaissance — os.hostname(), os.platform(), username, current working directory, output of shell commands (whoami, id, hostname -I via child_process), CI environment variables (GITHUB_*, GITLAB_*, JENKINS_*, etc.), AWS/GCP/Azure/Kubernetes cloud-metadata indicators, enumerated names of environment variables matching /KEY|SECRET|TOKEN|PASS|CRED|AUTH|API_|PRIVATE/i, and a boolean flag for the presence of NPM_TOKEN / NODE_AUTH_TOKEN — and exfiltrates it to the hardcoded Interactsh collaborator qtmetsrtvaujwklywbgw2wihc2lebzu0n.oast.fun via DNS lookups (dns.resolve of labeled subdomains), HTTPS POST to /depconf, and HTTP POST. The high version number (99.0.0) and generic internal-sounding package name are the standard dependency-confusion shape used to override private registry packages with a public squat. Source: ossf-package-analysis (0f74d699bfc5fcf83c6f2864f93ecd41d3d9f8613f45f6bfb3b6dd5eeb7a880e) The OpenSSF Package Analysis project identified 'list-issue-predecessor-dependencies-block' @ 99.0.0 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity. - The package executes one or more commands associated with malicious behavior.

    Affected packages

    Package

    Name: list-issue-predecessor-dependencies-block

    Purl: pkg:npm/list-issue-predecessor-dependencies-block

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    99.0.0
    MAL-2026-11430 | CVE-DB