MAL-2026-13438Malicious code in cewe-npm-cops (npm)
| Ecosystem | Package | Version |
|---|---|---|
| npm | cewe-npm-cops | 99.9.9 |
{"modified":"2026-08-06T16:16:37Z","published":"2026-08-06T16:16:37Z","schema_version":"1.7.4","id":"MAL-2026-13438","summary":"Malicious code in cewe-npm-cops (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (673bd57ca8632e768772381c7439b0b15008914879dfb5c22d42e40ce954c9e5)\ncewe-npm-cops@99.9.9 is a dependency-confusion probe. package.json declares scripts.preinstall = 'node preinstall.js'; preinstall.js reads os.hostname() and issues a dns.lookup against `<hostname>.zfir3qor582xqvyqm0tdc7xpqgw7ky8n.oastify.com`, an author-controlled Burp Collaborator (Interactsh) out-of-band host. Every npm install of this package unconditionally leaks the installer's machine hostname via DNS to a third-party OOB service. The package is otherwise hollow: version is set to 99.9.9 (max-version squat designed to override an internal package of the same name during resolution), main is an empty index.js, and author is the placeholder 'Your_HackerOne_Username'. The self-described 'harmless PoC' framing does not change the behavior: installer host identity is exfiltrated to an attacker-controlled endpoint at install time.\n","affected":[{"package":{"ecosystem":"npm","name":"cewe-npm-cops"},"versions":["99.9.9"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"preinstall.js","sha256":"1cc442fd670a919846700fa6c77d455d002d09cb56880d9c306ab14bbfa5cc05","tlsh":"7a01cbb018b4a6b0769566cae0c13027b5878db7ba49fc82b84fc71047c36fb835a038"},{"path":"package.json","sha256":"8bd6b3edf0cbc636e8e1243cb0542e2457da31debbfbe6c2640406f78a7b9aab","tlsh":"e5d0c2748950e23338c80aea18231202a9a94d5f0214bc046bc31059636a67b45bb60e"}],"package_integrity":[{"filename":"cewe-npm-cops-99.9.9.tgz","hashes":{"sha1":"143c5a4ef4f9695f87a70c2889059eeada82805e","sha512_sri":"sha512-bZnIZZxU6mpVfBnaLTKYvYHhBrz+l7N1J6Tc+FKtx0zlVbuyYxW8zWc0XKNzE6pmA2e/HA09cCiVowgTFDnLLw=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/cewe-npm-cops/v/99.9.9"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-016668","import_time":"2026-08-06T18:09:03.518025186Z","modified_time":"2026-08-06T16:16:37Z","sha256":"673bd57ca8632e768772381c7439b0b15008914879dfb5c22d42e40ce954c9e5","source":"amazon-inspector","versions":["99.9.9"]}]}}数据来源:OpenSSF Malicious Packages · Apache-2.0