MAL-2026-12386

    Dashboard / Malicious Package / MAL-2026-12386

    MAL-2026-12386

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in fundraiserservpp (npm)

    Details: Source: amazon-inspector (0bca913238607a18079a675e2fe652c25c04c2bbc62f5c577bb2b6d2424cd4a8) [email protected] runs `node index.js` as a `preinstall` lifecycle script on `npm install`. The script collects host metadata from the installer machine — `os.hostname()`, `os.platform()`, `os.arch()`, the user home directory path, and configured DNS servers — and issues an HTTPS POST to a hardcoded Burp Collaborator subdomain (`mrh99ucv1u3kyeba1020ae2t7kdc12pr.oastify.com/hit`) with that data as a JSON body. The beacon fires automatically at install time with no user interaction. The destination is an attacker-controlled out-of-band interaction endpoint typical of dependency-confusion reconnaissance, confirming to the operator that the package name was successfully resolved and installed inside a target build environment.

    Affected packages

    Package

    Name: fundraiserservpp

    Purl: pkg:npm/fundraiserservpp

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.9.0
    MAL-2026-12386 | CVE-DB