MAL-2026-14381

    Dashboard / Malicious Package / MAL-2026-14381

    MAL-2026-14381

    Published: 23 Aug 2026Last Modified: 24 Aug 2026

    Summary: Malicious code in fund-portfolio (npm)

    Details: Source: amazon-inspector (27ba065e8759299d381ed1c7abd5e7721037b4ea969a384a9e70cfb6bb799e17) Package declares `scripts.preinstall`: `node index.js`, causing index.js to run automatically on `npm install`. The script collects hostname, username, home directory, INIT_CWD, local IPv4, public egress IP (via api.ipify.org, icanhazip.com, ifconfig.me), DNS resolver IP and client subnet (via o-o.myaddr.l.google.com), and the parent project's package.json fields (name, author, repository, homepage). The collected JSON is exfiltrated to the hardcoded callback host `da51rv0hb2uc72tg4gvgdepinjcallbk1.oast.fun` (Interactsh/OAST) via DNS-chunked queries and HTTPS POST to `/poc/<uuid>`. The unscoped name is published at version 999.9.12 to defeat internal resolvers that fall back to the public npm registry, so any build referencing `fund-portfolio` without a private-registry pin will resolve to and execute this payload. Source: ossf-package-analysis (ffad2f6c37441c2924e67b1d506d9c26dc9cb2fae325b74a596102ea5ed403bf) The OpenSSF Package Analysis project identified 'fund-portfolio' @ 999.9.12 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity.

    Affected packages

    Package

    Name: fund-portfolio

    Purl: pkg:npm/fund-portfolio

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    999.9.12