MAL-2026-12419

    Dashboard / Malicious Package / MAL-2026-12419

    MAL-2026-12419

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in pp-react-worldready-v5 (npm)

    Details: Source: amazon-inspector (435cbd5d4dffc9d7e61222051c82a376bf6dd5a484760803953484ea0fa21b39) The tarball contains only package.json and vishu.js; the declared main (index.js) is absent, so the package has no library functionality. package.json.scripts.preinstall runs `node vishu.js`, which fires automatically on `npm install`. vishu.js resolves the installer's public IP via api.ipify.org, reads os.hostname() and GitHub Actions environment variables (CI, GITHUB_ACTIONS, GITHUB_WORKFLOW, GITHUB_RUN_ID, GITHUB_RUN_NUMBER, GITHUB_RUN_ATTEMPT), and sends them as query parameters in an HTTPS GET to https://webhook.site/1b840cbf-f1a4-4d79-bf11-f1ef62949110. It also issues a DNS lookup for `ping-<hostname>.your-collab-domain.oastify.com`, encoding the installer's hostname as a subdomain of a Burp Collaborator (OAST) host for out-of-band exfiltration. The package name resembles a typosquat pattern consistent with dependency-confusion reconnaissance.

    Affected packages

    Package

    Name: pp-react-worldready-v5

    Purl: pkg:npm/pp-react-worldready-v5

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0
    MAL-2026-12419 | CVE-DB