MAL-2026-12427
Dashboard / Malicious Package / MAL-2026-12427
MAL-2026-12427
Summary: Malicious code in remote_session_elements (npm)
Details: Source: amazon-inspector (3a2127d34a7d033e96e00a679891716647f0a00f7590ad738b43d985e83dda69) Package version 9999.0.0 is published with placeholder metadata ("Shared utility helpers.", no author) — the canonical shape of a dependency-confusion squat designed to override an internal package of the same name during resolution. On `npm install`, the `scripts.preinstall` hook runs `node callback.js`, which reads `os.hostname()`, `os.userInfo().username`, the current working directory, the configured npm registry, and CI-provided repository identifiers (e.g. `process.env.GITHUB_REPOSITORY`) and sends them via HTTP GET to `http://75.119.137.232:31337/depconfuse?pkg=...`, a hardcoded bare-IP endpoint over cleartext HTTP. This provides an external operator with the internal package name, host identity, and originating CI repository slug of every environment where the squat is installed — reconnaissance for further dependency-confusion attacks against the victim's internal package namespace.
Affected packages
Package
Name: remote_session_elements
Purl: pkg:npm/remote_session_elements
Affected ranges
Type: N/A
Events:
