MAL-2026-4418

    Dashboard / Malicious Package / MAL-2026-4418

    MAL-2026-4418

    Published: 20 May 2026Last Modified: 1 Sept 2026Aliases: 
    GHSA-wpmr-hxhp-4h27

    Summary: Malicious code in @pluxee-connect/api-client (npm)

    Details: Source: amazon-inspector (0f5056dda18e9a9f440db7379d09fa1f9f7ff087ac00d6684170cddd40c240e9) On `npm install`, postinstall.js collects `os.hostname()`, `os.userInfo()`, and `process.version` and transmits them over plain HTTP to `716bw4e4k31qif2nc1v658fb62ct0soh.oastify.com` (a Burp Collaborator out-of-band interaction subdomain), with DNS resolution providing a second exfil channel via subdomain encoding. The package itself is a near-empty shell — `index.js` exports only a `ConsentsStatus` enum — and is published at version 99.0.1, far above any plausible legitimate release for the `@pluxee-connect` scope. The structural shape (high-bumped version + trivial functional surface + lifecycle-time OOB beacon to oastify.com) is the canonical dependency-confusion attack against an internal scope. Any developer or CI system that resolves `@pluxee-connect/api-client` from public npm will leak machine identifiers to the attacker.

    Affected packages

    Package

    Name: @pluxee-connect/api-client

    Purl: pkg:npm/%40pluxee-connect/api-client

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    99.0.1
    99.0.0
    MAL-2026-4418 | CVE-DB