MAL-2026-4650

    Dashboard / Malicious Package / MAL-2026-4650

    MAL-2026-4650

    Published: 21 May 2026Last Modified: 26 May 2026

    Summary: Malicious code in pubnub-moderation-tool (npm)

    Details: Source: amazon-inspector (750918c1551873c10f69bc746538652a6adf047d6c76231a40832fff30b74938) package.json declares "preinstall": "node index.js", causing index.js to run automatically on npm install. The script collects os.hostname(), os.userInfo(), home directory, DNS server list, package metadata, and the contents of /etc/passwd and /etc/hosts, then HTTPS-POSTs the resulting JSON to vdcz3c5tmurvu7cqdfk9s524wv2nqee3.oastify.com — a Burp Collaborator subdomain used as an out-of-band exfiltration sink. The package contains no functionality matching its declared name; metadata fields (author, description) are empty and the package name impersonates PubNub branding, consistent with dependency-confusion / typosquat bait. Installing this package leaks installer host identity and local system files to an attacker on every install.

    Affected packages

    Package

    Name: pubnub-moderation-tool

    Purl: pkg:npm/pubnub-moderation-tool

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.3
    MAL-2026-4650 | CVE-DB