MAL-2026-11518

    Dashboard / Malicious Package / MAL-2026-11518

    MAL-2026-11518

    Published: 4 Aug 2026Last Modified: 4 Aug 2026

    Summary: Malicious code in exnesss (npm)

    Details: Source: amazon-inspector (184796b4aafee8400786643e9f43338886de2166171c62879cfd4c023655b487) Package name 'exnesss' typosquats 'exness'. The package.json declares scripts.postinstall: 'node./postinstall.js', and postinstall.js issues an HTTPS GET to a hardcoded Burp Collaborator subdomain (hteimcuxkeb6pacscuexz4d9y04rshg6.oastify.com) on every install. This fires automatically on `npm install`, contacting an out-of-band interaction host that reveals the installer's network/DNS metadata to the operator of that Collaborator instance. The package provides no advertised functionality to the installer beyond the beacon. Source: ossf-package-analysis (9547bba265ba397413387555d1bf269b1072ec4aba26409f22c72654c110cbf1) The OpenSSF Package Analysis project identified 'exnesss' @ 0.0.1 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity.

    Affected packages

    Package

    Name: exnesss

    Purl: pkg:npm/exnesss

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.0.1
    MAL-2026-11518 | CVE-DB