MAL-2026-6123

    Dashboard / Malicious Package / MAL-2026-6123

    MAL-2026-6123

    Published: 18 Jun 2026Last Modified: 18 Jun 2026

    Summary: Malicious code in @onum-releases/auth (npm)

    Details: Source: amazon-inspector (22d4bde1772d506f812e112fb8d6bfbf6a6f187dd823640f2cf15811f0d0633a) On `require('@onum-releases/auth')`, index.js reads `os.hostname()` and issues an HTTP GET to `auth.<hostname>.200majoeu01dk02xnjdajro1isojc90y.oastify.com`, transmitting the installer's host identifier to a Burp Collaborator out-of-band domain via both DNS resolution and HTTP. The package.json self-identifies as a 'dependency-confusion / scope-takeover demonstration' placeholder under the @onum-releases scope, so any build that mistakenly resolves an internal `@onum-releases/*` name to the public registry will leak its hostname to a third-party collaborator endpoint. Although labeled a PoC, the import-time beacon performs unconsented exfiltration of installer-side data to an attacker-controlled domain.

    Affected packages

    Package

    Name: @onum-releases/auth

    Purl: pkg:npm/%40onum-releases%2Fauth

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.3
    1.0.1
    1.0.2
    MAL-2026-6123 | CVE-DB