MAL-2026-12319

    Dashboard / Malicious Package / MAL-2026-12319

    MAL-2026-12319

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in @kite-js-tools/core (npm)

    Details: Source: amazon-inspector (5fc1e1caf8550f3daa91e586dd7b4eab7f5ec8f62acc12dce63d9d60c293e7c9) package.json declares preinstall and postinstall lifecycle scripts that fire automatically on npm install. The preinstall hook performs an HTTPS GET to https://d9hugcagp7gsdcl9dvs0frxfmqc1o8u86.oast.pro/ with the installer's hostname and process PID embedded in the URL path. The postinstall hook performs a DNS resolution against postinstall.<hostname>.d9hugcagp7gsdcl9dvs0frxfmqc1o8u86.oast.pro, leaking the same host identifier via DNS to the same collaborator subdomain. The destination is a Project Discovery Interactsh (OAST) subdomain — out-of-band callback infrastructure typically used to confirm code execution and exfiltrate identifying data from compromised machines. Installer-side host identifiers leave the machine to an attacker-controlled endpoint on every install.

    Affected packages

    Package

    Name: @kite-js-tools/core

    Purl: pkg:npm/%40kite-js-tools/core

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0
    MAL-2026-12319 | CVE-DB