MAL-2026-12497

    Dashboard / Malicious Package / MAL-2026-12497

    MAL-2026-12497

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in vscode-designer-14 (npm)

    Details: Source: amazon-inspector (dcf384e12e957c8d6b3d0014504f652cd2b6f3885f49820a2907865566bb6137) package.json declares a preinstall hook that runs index.js on npm install. index.js collects the installer's hostname, username, home directory, DNS server configuration, package metadata, and the contents of /etc/passwd and /etc/hosts, then POSTs the collected data over HTTPS to the hardcoded host slh4v8u1tz6gjo447tgf9rl3xu3mrcf1.oastify.com (a Burp Collaborator OAST subdomain). The package has no legitimate functionality that would justify reading local system files or beaconing host identifiers to an out-of-band interaction service; the shape matches a dependency-confusion / typosquat exfiltration beacon.

    Affected packages

    Package

    Name: vscode-designer-14

    Purl: pkg:npm/vscode-designer-14

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    14.0.1
    MAL-2026-12497 | CVE-DB