MAL-2026-5536

    Dashboard / Malicious Package / MAL-2026-5536

    MAL-2026-5536

    Published: 10 Jun 2026Last Modified: 11 Jun 2026

    Summary: Malicious code in zer0onedatetool (npm)

    Details: Source: amazon-inspector (73fd05fda74bbf13c6275d4da0fa80fece821cad03fb2237ae74ed24309eab52) The postinstall lifecycle script in this package issues curl POST requests to a subdomain of oastify.com — the out-of-band callback domain operated by Burp Collaborator / Project Discovery's interactsh. On every npm install, the script triggers an outbound HTTP request to an attacker-controlled OOB endpoint, which is the canonical fingerprint of a dependency-confusion / supply-chain reconnaissance payload (verifying the package landed in a victim environment and beaconing identifying host information out). The destination is not associated with any legitimate package functionality. Installer impact: any machine running `npm install` on this package automatically beacons to the attacker's OOB collector, leaking install-time host metadata and confirming code execution to the attacker.

    Affected packages

    Package

    Name: zer0onedatetool

    Purl: pkg:npm/zer0onedatetool

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0
    MAL-2026-5536 | CVE-DB