MAL-2026-5415

    Dashboard / Malicious Package / MAL-2026-5415

    MAL-2026-5415

    Published: 9 Jun 2026Last Modified: 9 Jun 2026

    Summary: Malicious code in @klapp-login-platform/routes (npm)

    Details: Source: amazon-inspector (ffe05a6af27bd4b583c0284a40129eb63f4dcb4a6197e74195a8bb85bf71d1e7) On `npm install`, the package's `preinstall` lifecycle hook executes `index.js`, which collects the installer's hostname, username, package install path (`__dirname`), current working directory, and package name, serializes them to JSON, hex-encodes the result, and exfiltrates the data through two channels: DNS lookups against subdomains of `d8jbmnsqcfu78dfs8vdg34ohqhirb4pbg.oast.live` (an Interactsh out-of-band callback host) and an HTTP POST to the bare IP endpoint `http://172.201.213.59:9090/c`. The package ships almost no functional code; its purpose is the beacon. The scope `@klapp-login-platform` paired with an inflated `99.0.2` version and a generic `routes` name fits the canonical dependency-confusion pattern of publishing a high-version public package to shadow an internal private package of the same name, causing affected build environments to resolve and install this attacker-controlled release.

    Affected packages

    Package

    Name: @klapp-login-platform/routes

    Purl: pkg:npm/%40klapp-login-platform%2Froutes

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    99.0.2
    99.0.0
    MAL-2026-5415 | CVE-DB