MAL-2026-5486
Dashboard / Malicious Package / MAL-2026-5486
MAL-2026-5486
Summary: Malicious code in menu-filter-widget-web (npm)
Details: Source: amazon-inspector (bed4a7ece362ef59f2b621b3f64d06e899740c8ca8d73e437145d48b960187ce) package.json declares a postinstall lifecycle hook that runs callback.js on every npm install. callback.js reads os.hostname() and sends it to a hardcoded oastify.com (Burp Collaborator) URL via HTTPS GET, with a fallback DNS lookup that embeds the hostname as a subdomain label. Both channels carry a unique token plus the installer's hostname, registering the install with a remote attacker-controlled collaborator on every install. The package self-describes as a 'PoC' but is published to the public registry, so any installer leaks host identity automatically without consent.
Affected packages
Package
Name: menu-filter-widget-web
Purl: pkg:npm/menu-filter-widget-web
Affected ranges
Type: N/A
Events:
