MAL-2026-13438

    Dashboard / Malicious Package / MAL-2026-13438

    MAL-2026-13438

    Published: 6 Aug 2026Last Modified: 6 Aug 2026

    Summary: Malicious code in cewe-npm-cops (npm)

    Details: Source: amazon-inspector (673bd57ca8632e768772381c7439b0b15008914879dfb5c22d42e40ce954c9e5) [email protected] is a dependency-confusion probe. package.json declares scripts.preinstall = 'node preinstall.js'; preinstall.js reads os.hostname() and issues a dns.lookup against `<hostname>.zfir3qor582xqvyqm0tdc7xpqgw7ky8n.oastify.com`, an author-controlled Burp Collaborator (Interactsh) out-of-band host. Every npm install of this package unconditionally leaks the installer's machine hostname via DNS to a third-party OOB service. The package is otherwise hollow: version is set to 99.9.9 (max-version squat designed to override an internal package of the same name during resolution), main is an empty index.js, and author is the placeholder 'Your_HackerOne_Username'. The self-described 'harmless PoC' framing does not change the behavior: installer host identity is exfiltrated to an attacker-controlled endpoint at install time.

    Affected packages

    Package

    Name: cewe-npm-cops

    Purl: pkg:npm/cewe-npm-cops

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    99.9.9
    MAL-2026-13438 | CVE-DB