MAL-2026-12426

    Dashboard / Malicious Package / MAL-2026-12426

    MAL-2026-12426

    Published: 5 Aug 2026Last Modified: 1 Sept 2026

    Summary: Malicious code in relativity-foundation-core (npm)

    Details: Source: amazon-inspector (0c61f9e4ea2d66ea8dd4b9018fa109fe65d00cb0de98b3f8551a95ca3859af5d) package.json declares a preinstall script that runs a Node one-liner collecting os.hostname(), process.env.USER/USERNAME, cwd, npm_config_registry, CI, GITHUB_REPOSITORY, JENKINS_URL, and platform, base64-encodes the JSON blob, and issues an HTTPS GET to https://aiwi9di43fzbjwncfrimdvkgu701orcg.oastify.com/?d=<base64> on every `npm install`. index.js is empty, so the package's only effect is this reconnaissance beacon. The oastify.com destination is a Burp Collaborator subdomain used as an attacker-controlled out-of-band exfiltration sink.

    Affected packages

    Package

    Name: relativity-foundation-core

    Purl: pkg:npm/relativity-foundation-core

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    6.8.2
    MAL-2026-12426 | CVE-DB