MAL-2026-13965

    Dashboard / Malicious Package / MAL-2026-13965

    MAL-2026-13965

    Published: 13 Aug 2026Last Modified: 13 Aug 2026

    Summary: Malicious code in nc-verify-127942 (npm)

    Details: Source: amazon-inspector (3ea69188e179cd73aa9f200d63e8faceb5d3aae622a8fe2d86bf7ae761b5f1e0) nc-verify-127942 declares a postinstall lifecycle hook ("postinstall": "node install-cb.js") that runs automatically on npm install. The install-cb.js script issues an HTTPS request and a DNS lookup to a Burp Collaborator subdomain under oastify.com (nc-verify-127942.owoemjgpf2c4qxqet92hexzvym4dsq6skvoa2cr.oastify.com), which confirms code execution on the installer's host and leaks install-side network identifiers (source IP, resolver) to an operator-controlled out-of-band endpoint. The package's own metadata labels it as a proof-of-concept for RCE verification; installing it in a normal developer or CI environment fires the beacon without any user interaction.

    Affected packages

    Package

    Name: nc-verify-127942

    Purl: pkg:npm/nc-verify-127942

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0
    MAL-2026-13965 | CVE-DB