MAL-2026-14137

    Dashboard / Malicious Package / MAL-2026-14137

    MAL-2026-14137

    Published: 18 Aug 2026Last Modified: 18 Aug 2026

    Summary: Malicious code in mtslink-depconf-probe-profileusername (npm)

    Details: Source: amazon-inspector (f679922753b7a59c59af851ae74275b5d4760b13fc516bc8c68e8e9568393dc6) Package ships an empty index.js and a preinstall lifecycle script that performs a DNS lookup against probe.4otph6fase1x2won0hrfzul2wt2qqge5.oastify.com (Burp Collaborator out-of-band infrastructure). On npm install, the installer's resolver contacts the attacker-controlled subdomain, leaking install-time telemetry (resolver IP, timing, and the unique subdomain identifier) to a third party. The package name pattern and description ('Bug bounty auth probe - safe empty package') indicate a dependency-confusion / typosquat probe targeting an internal namespace; the only functionality is the outbound beacon.

    Affected packages

    Package

    Name: mtslink-depconf-probe-profileusername

    Purl: pkg:npm/mtslink-depconf-probe-profileusername

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0
    MAL-2026-14137 | CVE-DB