MAL-2026-12669

    Dashboard / Malicious Package / MAL-2026-12669

    MAL-2026-12669

    Published: 5 Aug 2026Last Modified: 6 Aug 2026

    Summary: Malicious code in dbk-ui-forms (npm)

    Details: Source: amazon-inspector (36c6972ca0999559f2a4548843790c8000451acb4869da3c83d0357a655586ba) On `npm install`, the package's preinstall hook runs index.js which collects host identity (hostname, username, homedir, network interfaces, uid), output of `whoami`/`id`/`pwd`/`uname -a`, and the names of process.env variables matching a broad credential regex (key/token/secret/pass/auth/cred/npm/ci/build/jenkins/github/gitlab/aws/azure). The collected JSON is transmitted to the hardcoded Interactsh subdomain `ycwyyoimdcluajepubah2mvmkibt4h5wm.oast.fun` via HTTPS POST, HTTP POST, and DNS-encoded lookups. The package name and version (99.0.1) are consistent with a dependency-confusion beacon targeting internal build systems that resolve an unclaimed name from the public registry.

    Affected packages

    Package

    Name: dbk-ui-forms

    Purl: pkg:npm/dbk-ui-forms

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    99.0.1
    99.0.0
    MAL-2026-12669 | CVE-DB