MAL-2026-13436
Dashboard / Malicious Package / MAL-2026-13436
MAL-2026-13436
Summary: Malicious code in @wbnr/frontend-shared (npm)
Details: Source: amazon-inspector (6208a0da32b8b7ae795d85ecbf95788b876729db08b0a595ad24f05a02dbbdbe) The package declares a preinstall lifecycle script (preinstall.js) that automatically runs on npm install. The script reads the installer's OS username (from process.env USER/USERNAME) and hostname (os.hostname()), embeds them into a subdomain of a hardcoded 4otph6fase1x2won0hrfzul2wt2qqge5.oastify.com callback host, and transmits them via both a DNS lookup and an HTTPS GET to that host at path /depconf/. The behavior is consistent with a dependency-confusion probe using Burp Collaborator (oastify.com) infrastructure; installer identifiers (username, internal hostname, timestamp, package name) are disclosed to a third-party callback domain on every install.
References: https://www.npmjs.com/package/@wbnr/frontend-shared/v/99.0.0, https://www.npmjs.com/package/@wbnr/frontend-shared/v/99.0.1
Affected packages
Package
Name: @wbnr/frontend-shared
Purl: pkg:npm/%40wbnr/frontend-shared
Affected ranges
Type: N/A
Events:
