MAL-2026-4264
Dashboard / Malicious Package / MAL-2026-4264
MAL-2026-4264
Summary: Malicious code in dds-js-idl (npm)
Details: Source: amazon-inspector (c864bc6e21a3795faba4de876942dfffa4baed76c926d96d52c83c32d1f49f69) On `npm install`, postinstall.js runs `whoami` via execSync and collects os.hostname(), os.platform(), cwd, and CI/GitHub env vars, then exfiltrates them over HTTPS GET to `lg5ys3jebfzwk366pilidbmah1nsbszh.oastify.com/nasa/dds-js-canary/` and additionally performs a DNS lookup of `${whoami}.lg5ys3jebfzwk366pilidbmah1nsbszh.oastify.com` as a DNS-channel fallback that defeats egress HTTPS filtering. The package self-describes as a `Security research canary — NASA VDP`, but it fires on every install without consent and leaks installer identity and repository/CI context to a third-party Interactsh (oastify.com) collector controlled by the canary operator. Regardless of stated research intent, the structural behavior is install-time host fingerprinting and out-of-band exfiltration. Source: ossf-package-analysis (282ab4387de68701d586cdeb6635a576abea042584decbb31640112e9292e83a) The OpenSSF Package Analysis project identified 'dds-js-idl' @ 1.0.0 (npm) as malicious. It is considered malicious because: - The package executes one or more commands associated with malicious behavior.
References: https://www.npmjs.com/package/dds-js-idl/v/1.0.1, https://www.npmjs.com/package/dds-js-idl/v/1.0.0
Affected packages
Package
Name: dds-js-idl
Purl: pkg:npm/dds-js-idl
Affected ranges
Type: N/A
Events:
