MAL-2026-13626

    Dashboard / Malicious Package / MAL-2026-13626

    MAL-2026-13626

    Published: 7 Aug 2026Last Modified: 7 Aug 2026

    Summary: Malicious code in @mrbenty8jf1p9y5/oidc-bind-canary (npm)

    Details: Source: amazon-inspector (1a9ed4acf296e53ad5955f759a0f0692d641781b1bd4e67ada1c116216f96fc3) The package's postinstall lifecycle script issues an HTTPS request from the installer's machine to a Cloudflare tunnel at wiki-shared-carlos-exempt.trycloudflare.com on path /token-capture. The request is sent with the Host header spoofed to dependabot-api.githubapp.com and with TLS certificate validation disabled (rejectUnauthorized:false), disguising the callout as legitimate GitHub Dependabot traffic. The destination path name (/token-capture) and the disguise mechanics indicate an install-time beacon to an attacker-controlled listener, firing automatically on npm install.

    Affected packages

    Package

    Name: @mrbenty8jf1p9y5/oidc-bind-canary

    Purl: pkg:npm/%40mrbenty8jf1p9y5/oidc-bind-canary

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.0.3
    MAL-2026-13626 | CVE-DB