MAL-2026-12386Malicious code in fundraiserservpp (npm)
| Ecosystem | Package | Version |
|---|---|---|
| npm | fundraiserservpp | 1.9.0 |
| npm | fundraiserservpp | 2.0.0 |
{"schema_version":"1.7.4","id":"MAL-2026-12386","published":"2026-08-05T12:59:29Z","modified":"2026-08-05T16:16:01.948924270Z","summary":"Malicious code in fundraiserservpp (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (0bca913238607a18079a675e2fe652c25c04c2bbc62f5c577bb2b6d2424cd4a8)\nfundraiserservpp@2.0.0 runs `node index.js` as a `preinstall` lifecycle script on `npm install`. The script collects host metadata from the installer machine — `os.hostname()`, `os.platform()`, `os.arch()`, the user home directory path, and configured DNS servers — and issues an HTTPS POST to a hardcoded Burp Collaborator subdomain (`mrh99ucv1u3kyeba1020ae2t7kdc12pr.oastify.com/hit`) with that data as a JSON body. The beacon fires automatically at install time with no user interaction. The destination is an attacker-controlled out-of-band interaction endpoint typical of dependency-confusion reconnaissance, confirming to the operator that the package name was successfully resolved and installed inside a target build environment.\n","affected":[{"package":{"name":"fundraiserservpp","ecosystem":"npm"},"versions":["1.9.0","2.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"index.js","sha256":"268e7088c0eb0140719c86be7d00da47f74f03875183b8bd3b48d6d4b9c6e863","tlsh":"aff081d4e6f55a710b7699d0b0a255069333d662740ff4d05fc8027607cddf801b16f4"}],"package_integrity":[{"filename":"fundraiserservpp-1.9.0.tgz","hashes":{"sha1":"dfb6a2a99627b2ac502aba8eeb2f914ac2316178","sha512_sri":"sha512-Iok3BkQbCVAQeDRksJMKTCAmPtt9qLKC8UivPZjVnAaRkdwMJDzfvsM5wicAzhvx6MeAmIIhZV85sXHolnJbFA=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/fundraiserservpp/v/1.9.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/fundraiserservpp/v/2.0.0"}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-014837","import_time":"2026-08-05T13:08:50.221303978Z","modified_time":"2026-08-05T12:59:29Z","sha256":"542a9a32b033b5188849fa81e6ec448528308f1251256d861ee7917a7cdcb473","source":"amazon-inspector","versions":["1.9.0"]},{"id":"IN-MAL-2026-015807","import_time":"2026-08-05T16:13:47.616663509Z","modified_time":"2026-08-05T15:52:56Z","sha256":"0bca913238607a18079a675e2fe652c25c04c2bbc62f5c577bb2b6d2424cd4a8","source":"amazon-inspector","versions":["2.0.0"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}数据来源:OpenSSF Malicious Packages · Apache-2.0