MAL-2026-12669
Dashboard / Malicious Package / MAL-2026-12669
MAL-2026-12669
Summary: Malicious code in dbk-ui-forms (npm)
Details: Source: amazon-inspector (36c6972ca0999559f2a4548843790c8000451acb4869da3c83d0357a655586ba) On `npm install`, the package's preinstall hook runs index.js which collects host identity (hostname, username, homedir, network interfaces, uid), output of `whoami`/`id`/`pwd`/`uname -a`, and the names of process.env variables matching a broad credential regex (key/token/secret/pass/auth/cred/npm/ci/build/jenkins/github/gitlab/aws/azure). The collected JSON is transmitted to the hardcoded Interactsh subdomain `ycwyyoimdcluajepubah2mvmkibt4h5wm.oast.fun` via HTTPS POST, HTTP POST, and DNS-encoded lookups. The package name and version (99.0.1) are consistent with a dependency-confusion beacon targeting internal build systems that resolve an unclaimed name from the public registry.
References: https://www.npmjs.com/package/dbk-ui-forms/v/99.0.1, https://www.npmjs.com/package/dbk-ui-forms/v/99.0.0
Affected packages
Package
Name: dbk-ui-forms
Purl: pkg:npm/dbk-ui-forms
Affected ranges
Type: N/A
Events:
