MAL-2026-13481
Dashboard / Malicious Package / MAL-2026-13481
MAL-2026-13481
Summary: Malicious code in cdf-tag-commander-helper (npm)
Details: Source: amazon-inspector (945179057c5bd93b985c3c532baa35379ce9dd9603e26d17e63201beb25868ae) The preinstall lifecycle script in [email protected] runs automatically on `npm install`. It executes `whoami` and `hostname`, retrieves the machine's public IP via ifconfig.me, and issues a plain-HTTP GET to a hardcoded Interactsh-style out-of-band callback subdomain (kwphewvexhjbtfduscqybx6q7c862eh0g.oast.fun), passing the three values as query parameters. The README states that the package makes no network requests, which contradicts the shipped code. The behavior is a reconnaissance beacon consistent with dependency-confusion targeting: on install, an attacker learns which internal build hosts and user accounts have resolved this package name.
References: https://www.npmjs.com/package/cdf-tag-commander-helper/v/3.6.2, https://www.npmjs.com/package/cdf-tag-commander-helper/v/3.1.1
Affected packages
Package
Name: cdf-tag-commander-helper
Purl: pkg:npm/cdf-tag-commander-helper
Affected ranges
Type: N/A
Events:
