MAL-2026-14410

    Dashboard / Malicious Package / MAL-2026-14410

    MAL-2026-14410

    Published: 24 Aug 2026Last Modified: 24 Aug 2026

    Summary: Malicious code in @temptation.js/utils (npm)

    Details: Source: amazon-inspector (3b8ac41747a5c926627c28c9f1a651df91cd3447b07ca4cafabc1916004d1e70) The package registers a preinstall hook (node index.js) that runs on npm install and harvests installer-side data: os.hostname(), OS username, home directory, local IPv4, public IP resolved via https://api.ipify.org / https://icanhazip.com / https://ifconfig.me, DNS resolver info, INIT_CWD, parent project package.json fields, CI context (GitHub Actions/GitLab/Jenkins/Azure DevOps repo, actor, run id), AWS_REGION, npm registry URL, git user.email domain, and the output of `gh api user --jq.login` and `npm whoami` — using the installer's authenticated gh/npm CLI sessions to attribute the install to a real developer account. The collected JSON is hex-encoded, split into 60-character chunks, and exfiltrated via DNS resolutions of the form `<i>-<hex>.u-<uuid>.da51rv0hb2uc72tg4gvgdepinjcallbk1.oast.fun` (an OAST/interactsh callback host) as well as HTTPS/HTTP POSTs to /poc/<uuid> at the same host. A source comment describes the DNS channel as designed to survive corporate egress filtering. The version number 999.9.15 is a dependency-confusion overshoot intended to win private-name resolution against an internal package of the same name. Source: ossf-package-analysis (c8d0cfc44fc0fd8c597831c7da133a0e02ba0f1644f9777edb7629099bb367b8) The OpenSSF Package Analysis project identified '@temptation.js/utils' @ 999.9.16 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity.

    Affected packages

    Package

    Name: @temptation.js/utils

    Purl: pkg:npm/%40temptation.js/utils

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    999.9.16
    999.9.15