MAL-2026-4635

    Dashboard / Malicious Package / MAL-2026-4635

    MAL-2026-4635

    Published: 21 May 2026Last Modified: 26 May 2026

    Summary: Malicious code in payment-account-input-selector (npm)

    Details: Source: amazon-inspector (12187e6fb4ae4d3a411cea0c3ec8b995e1091a9cf78219db9fbcdac87540aabf) On `npm install`, preinstall.js collects hostname, username, platform, cwd, timestamp, and a full dump of os.networkInterfaces() and HTTP-GETs them as query parameters to a hardcoded Burp Collaborator (oastify.com) endpoint. Errors are silently swallowed (the source comment notes 'Silent fail to avoid detection'). The package's metadata advertises an Oracle JET payment account selector but ships only a 5-line stub for index.js — the only real logic is the install-time beacon. The combination of empty author metadata, generic 'oracle/jet/payment' keywords, hollow main entry, and a recon-only preinstall is consistent with a dependency-confusion probe against an internal Oracle JET package name, with installer host/network topology exfiltrated to the attacker's OAST collector.

    Affected packages

    Package

    Name: payment-account-input-selector

    Purl: pkg:npm/payment-account-input-selector

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0