MAL-2026-4650
Dashboard / Malicious Package / MAL-2026-4650
MAL-2026-4650
Summary: Malicious code in pubnub-moderation-tool (npm)
Details: Source: amazon-inspector (750918c1551873c10f69bc746538652a6adf047d6c76231a40832fff30b74938) package.json declares "preinstall": "node index.js", causing index.js to run automatically on npm install. The script collects os.hostname(), os.userInfo(), home directory, DNS server list, package metadata, and the contents of /etc/passwd and /etc/hosts, then HTTPS-POSTs the resulting JSON to vdcz3c5tmurvu7cqdfk9s524wv2nqee3.oastify.com — a Burp Collaborator subdomain used as an out-of-band exfiltration sink. The package contains no functionality matching its declared name; metadata fields (author, description) are empty and the package name impersonates PubNub branding, consistent with dependency-confusion / typosquat bait. Installing this package leaks installer host identity and local system files to an attacker on every install.
Affected packages
Package
Name: pubnub-moderation-tool
Purl: pkg:npm/pubnub-moderation-tool
Affected ranges
Type: N/A
Events:
