MAL-2026-4479

    Dashboard / Malicious Package / MAL-2026-4479

    MAL-2026-4479

    Published: 21 May 2026Last Modified: 1 Sept 2026Aliases: 
    GHSA-4vj8-cm74-gcx3

    Summary: Malicious code in anthropic-shared-logger (npm)

    Details: Source: amazon-inspector (e54ef50a83e2f379965286ed404d16ca3389a9ce5c8593718ef4e6f307cc6084) This package impersonates Anthropic's internal namespace and self-describes as 'Full RCE PoC - Alex Birsan Style'. Its package.json declares a postinstall hook that, on every `npm install`, fetches the installer's public IP from api.ipify.org, runs `id || ver && whoami && hostname` via child_process.exec, and POSTs the hostname, current working directory, USERDOMAIN/COMPANY environment variables, IP address, and command output to a hardcoded Interactsh OOB endpoint at lszakfghwnvxspyfcmaabd1css99rnq3w.oast.fun over plain HTTP. The combination of namespace impersonation, automatic install-time shell execution, and host reconnaissance exfiltration to attacker-controlled out-of-band infrastructure is a canonical Birsan-style dependency confusion attack. Any build system that mis-resolves this name to the public registry leaks identity and host data to the attacker, enabling targeted follow-on compromise.

    Affected packages

    Package

    Name: anthropic-shared-logger

    Purl: pkg:npm/anthropic-shared-logger

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    8.0.5
    MAL-2026-4479 | CVE-DB