MAL-2026-4525

    Dashboard / Malicious Package / MAL-2026-4525

    MAL-2026-4525

    Published: 20 May 2026Last Modified: 1 Sept 2026Aliases: 
    GHSA-jxg3-fwfv-fjwf

    Summary: Malicious code in claude-internal-utils (npm)

    Details: Source: amazon-inspector (24a94a290c15f2b6cdaf351590455cd597bb2881f7bbcf1609fbfbd8031e491f) Package name impersonates an internal Anthropic 'claude-*' namespace and the description field self-identifies as 'Alex Birsan Style' dependency-confusion bait. The package ships no library code; its only effect is a postinstall lifecycle hook that runs an inline node one-liner which fetches the installer's public IP from api.ipify.org, executes `id || ver && whoami && hostname` via child_process.exec, and POSTs hostname, cwd, USERDOMAIN/COMPANY env vars, public IP, package name, and the command output as JSON to a hardcoded attacker subdomain at lszakfghwnvxspyfcmaabd1css99rnq3w.oast.fun (an out-of-band interaction service commonly used for exfiltration). Fires automatically on `npm install`, before any consumer code runs.

    Affected packages

    Package

    Name: claude-internal-utils

    Purl: pkg:npm/claude-internal-utils

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    9.0.5