MAL-2026-14378Malicious code in stillm4ddpocs-rtest-bravo (npm)
| Ecosystem | Package | Version |
|---|---|---|
| npm | stillm4ddpocs-rtest-bravo | 999.9.10 |
| npm | stillm4ddpocs-rtest-bravo | 999.9.9 |
{"modified":"2026-08-23T03:27:44Z","published":"2026-08-23T03:13:51Z","schema_version":"1.7.4","id":"MAL-2026-14378","summary":"Malicious code in stillm4ddpocs-rtest-bravo (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (15e4272ba48bc8a81c8a76e7948aed6974b40956c151f05a613456e92690f5f2)\npackage.json declares scripts.preinstall = 'node index.js', so npm install auto-executes index.js. The script collects hostname, username, home directory, local IPv4, INIT_CWD, and the public egress IP (queried from api.ipify.org, icanhazip.com, and ifconfig.me), and reads the consuming project's package.json (INIT_CWD/package.json) to extract name, author, repository, and homepage — identifying which internal package name resolved to this public package. The payload is transmitted to the hardcoded collector da51rv0hb2uc72tg4gvgdepinjcallbk1.oast.fun via HTTPS POST to /poc/<uuid> and, in parallel, hex-encoded and chunked into DNS labels (`<idx>-<chunk>.u-<uuid>.<callback>`) resolved via dns.resolve, providing a fallback exfiltration channel when outbound HTTP is filtered. The package's self-description as a dependency-confusion research PoC does not change the behavior: installer host and parent-project identifiers are shipped to a third-party Interactsh collector without installer consent.\n","affected":[{"package":{"ecosystem":"npm","name":"stillm4ddpocs-rtest-bravo"},"versions":["999.9.10","999.9.9"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"index.js","sha256":"b8bbccbb12bdcb2e4f40f0a44a2ae1d1d1c43e898351e23bf6542a4c6376418f","tlsh":"2fe1a69712fa203012623ab8279f58957333d523338aebd0b98d43645fd727d53b26da"}],"package_integrity":[{"filename":"stillm4ddpocs-rtest-bravo-999.9.10.tgz","hashes":{"sha1":"066c0c115cf1290f07f060a7ef49cbf7373adfb2","sha512_sri":"sha512-N3mD6g3ixMFPYC4a+X3RnE8sgZxRpx+TSHIP4UeKOn5dJ7yluT+MjyY8MEvwvHqKzVcf6oZElhiq5nJSDqqe7A=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/stillm4ddpocs-rtest-bravo/v/999.9.10"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/stillm4ddpocs-rtest-bravo/v/999.9.9"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-018564","import_time":"2026-08-23T03:25:55.728189159Z","modified_time":"2026-08-23T03:13:51Z","sha256":"15e4272ba48bc8a81c8a76e7948aed6974b40956c151f05a613456e92690f5f2","source":"amazon-inspector","versions":["999.9.10"]},{"id":"IN-MAL-2026-018565","import_time":"2026-08-23T03:25:55.821554142Z","modified_time":"2026-08-23T03:13:58Z","sha256":"fd3e9cff049df53120f980d470f575d8723edc6a3ea29a09b78f7f9aedf4a006","source":"amazon-inspector","versions":["999.9.9"]}]}}数据来源:OpenSSF Malicious Packages · Apache-2.0