MAL-2026-6123
Dashboard / Malicious Package / MAL-2026-6123
MAL-2026-6123
Summary: Malicious code in @onum-releases/auth (npm)
Details: Source: amazon-inspector (22d4bde1772d506f812e112fb8d6bfbf6a6f187dd823640f2cf15811f0d0633a) On `require('@onum-releases/auth')`, index.js reads `os.hostname()` and issues an HTTP GET to `auth.<hostname>.200majoeu01dk02xnjdajro1isojc90y.oastify.com`, transmitting the installer's host identifier to a Burp Collaborator out-of-band domain via both DNS resolution and HTTP. The package.json self-identifies as a 'dependency-confusion / scope-takeover demonstration' placeholder under the @onum-releases scope, so any build that mistakenly resolves an internal `@onum-releases/*` name to the public registry will leak its hostname to a third-party collaborator endpoint. Although labeled a PoC, the import-time beacon performs unconsented exfiltration of installer-side data to an attacker-controlled domain.
References: https://www.npmjs.com/package/@onum-releases/auth/v/1.0.3, https://www.npmjs.com/package/@onum-releases/auth/v/1.0.1, https://www.npmjs.com/package/@onum-releases/auth/v/1.0.2
Affected packages
Package
Name: @onum-releases/auth
Purl: pkg:npm/%40onum-releases%2Fauth
Affected ranges
Type: N/A
Events:
