MAL-2026-11518
Dashboard / Malicious Package / MAL-2026-11518
MAL-2026-11518
Summary: Malicious code in exnesss (npm)
Details: Source: amazon-inspector (184796b4aafee8400786643e9f43338886de2166171c62879cfd4c023655b487) Package name 'exnesss' typosquats 'exness'. The package.json declares scripts.postinstall: 'node./postinstall.js', and postinstall.js issues an HTTPS GET to a hardcoded Burp Collaborator subdomain (hteimcuxkeb6pacscuexz4d9y04rshg6.oastify.com) on every install. This fires automatically on `npm install`, contacting an out-of-band interaction host that reveals the installer's network/DNS metadata to the operator of that Collaborator instance. The package provides no advertised functionality to the installer beyond the beacon. Source: ossf-package-analysis (9547bba265ba397413387555d1bf269b1072ec4aba26409f22c72654c110cbf1) The OpenSSF Package Analysis project identified 'exnesss' @ 0.0.1 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity.
References: https://www.npmjs.com/package/exnesss/v/0.0.1
Affected packages
Package
Name: exnesss
Purl: pkg:npm/exnesss
Affected ranges
Type: N/A
Events:
