MAL-2026-13442
Dashboard / Malicious Package / MAL-2026-13442
MAL-2026-13442
Summary: Malicious code in content-common (npm)
Details: Source: amazon-inspector (5656ce6bbda8526587e40810d90b3188e11d507ebb13168203384bfac6b5ec1b) [email protected] declares a preinstall lifecycle script in package.json that executes `node -e` to perform an HTTP GET to a unique subdomain of oastify.com (Burp Suite Collaborator): http://fyhmr907kt8qphysiu67m1p00r6iu8ix.oastify.com. This fires automatically on `npm install`, confirming arbitrary code execution on the installer's host and leaking the installer's public IP and DNS resolver metadata via the unique subdomain lookup to the attacker-controlled collaborator endpoint. The package's self-declared 'Mozilla bug bounty PoC' framing does not change the behavior: any consumer who installs this version triggers the out-of-band callback. The version number 99.9.9 is also consistent with a dependency-confusion / typosquat probe against an internal package name.
Affected packages
Package
Name: content-common
Purl: pkg:npm/content-common
Affected ranges
Type: N/A
Events:
