MAL-2026-13442

    Dashboard / Malicious Package / MAL-2026-13442

    MAL-2026-13442

    Published: 6 Aug 2026Last Modified: 6 Aug 2026

    Summary: Malicious code in content-common (npm)

    Details: Source: amazon-inspector (5656ce6bbda8526587e40810d90b3188e11d507ebb13168203384bfac6b5ec1b) [email protected] declares a preinstall lifecycle script in package.json that executes `node -e` to perform an HTTP GET to a unique subdomain of oastify.com (Burp Suite Collaborator): http://fyhmr907kt8qphysiu67m1p00r6iu8ix.oastify.com. This fires automatically on `npm install`, confirming arbitrary code execution on the installer's host and leaking the installer's public IP and DNS resolver metadata via the unique subdomain lookup to the attacker-controlled collaborator endpoint. The package's self-declared 'Mozilla bug bounty PoC' framing does not change the behavior: any consumer who installs this version triggers the out-of-band callback. The version number 99.9.9 is also consistent with a dependency-confusion / typosquat probe against an internal package name.

    Affected packages

    Package

    Name: content-common

    Purl: pkg:npm/content-common

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    99.9.9
    MAL-2026-13442 | CVE-DB