MAL-2026-5459

    Dashboard / Malicious Package / MAL-2026-5459

    MAL-2026-5459

    Published: 9 Jun 2026Last Modified: 9 Jun 2026

    Summary: Malicious code in @dktunited/anly-tracker-v2 (npm)

    Details: Source: amazon-inspector (8a8893b914c3ba3139a3c8cede191521742237aa7c1c5d64f7ee45dbc5f636a6) scripts/postinstall.js runs unconditionally during `npm install` and exfiltrates installer-side identifiers to an attacker-controlled out-of-band collector. The script fetches the installer's public IP from api.ipify.org, then collects `os.userInfo().username`, `os.hostname()`, `process.cwd()`, the package name, and the resolved IP, and transmits them to the hardcoded host `xjaipnfhcpawuhzlgzkzub8mc0rqdiuyp.oast.fun` (an Interactsh OOB collector) via two channels: a `dns.lookup` of a hex-encoded subdomain and an `https.request` to `/poc` carrying the JSON payload base64-encoded in an `x-poc` header. The package is published at version 99.99.99 — the canonical dependency-confusion squat marker designed to outrank any internal `@dktunited/anly-tracker-v2` package by semver. Whether labeled a bug-bounty PoC by the author or not, it is live on the public registry and will harm any build system that resolves it.

    Affected packages

    Package

    Name: @dktunited/anly-tracker-v2

    Purl: pkg:npm/%40dktunited%2Fanly-tracker-v2

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    99.99.99