MAL-2026-13882

    Dashboard / Malicious Package / MAL-2026-13882

    MAL-2026-13882

    Published: 12 Aug 2026Last Modified: 12 Aug 2026

    Summary: Malicious code in verify-cli (npm)

    Details: Source: amazon-inspector (081d3a8717b3f05f688cdde25d2b0de315dd9b1f400382e0db00d53f8ca82d6b) package.json declares `preinstall: node index.js`, which runs automatically on `npm install`. index.js shells out via child_process and curl to POST the installer's `whoami`, `hostname`, and `id` output along with base64-encoded contents of `/etc/passwd`, `/etc/hosts`, and (if readable) `/etc/shadow` to a hardcoded out-of-band interactsh/OAST endpoint at `5f8a1ed70fb7761d678agw9bucryyyyyb.oast.site`. Package metadata shows an implausible version (99.0.0), placeholder description ("Nodejs SDK for Redacted"), and a nonexistent dependency, consistent with a dependency-confusion / typosquat beacon rather than a legitimate SDK.

    Affected packages

    Package

    Name: verify-cli

    Purl: pkg:npm/verify-cli

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    99.0.0