MAL-2026-14411Malicious code in dpg-media-7ehemel (npm)
| 版本 | 状态 | 大小 | SHA-256 | 获取方式 |
|---|---|---|---|---|
999.9.15 | archived | — | — | VIP 下载 |
| Ecosystem | Package | Version |
|---|---|---|
| npm | dpg-media-7ehemel | 999.9.15 |
{"schema_version":"1.7.4","id":"MAL-2026-14411","published":"2026-08-24T14:00:56Z","modified":"2026-08-24T16:51:04.531730565Z","summary":"Malicious code in dpg-media-7ehemel (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (4a904ad03d7041e21fe41a101c6a2db4a6aa3106f7b36394208bb4a5a39ee594)\nnpm package dpg-media-7ehemel@999.9.15 executes `node index.js` from a `preinstall` lifecycle script that harvests installer identity and environment context and beacons it to the hardcoded host `da51rv0hb2uc72tg4gvgdepinjcallbk1.oast.fun`. The script collects `os.hostname()`, username/home/cwd/INIT_CWD, local and public IP addresses (via https.get to api.ipify.org / icanhazip.com / ifconfig.me), resolver IPs, and CI metadata (repo, actor, run id, workflow, AWS region), and spawns `gh api user --jq.login`, `npm whoami`, and `git config user.email` to attribute the environment to a specific developer/org, plus reads parent project package.json fields. The payload is serialized as JSON, hex-encoded, chunked to 60-character DNS labels, and exfiltrated both via `dns.resolve` subdomain queries (`${i}-${c}.u-${uuid}.<callback>`) and via HTTP/HTTPS POST to `/poc/${uuid}` on the same callback host. The version string 999.9.15 and the developer-identity harvest are characteristic of a dependency-confusion beacon targeting a private-scope name. Any self-description as authorized research is contradicted by the DNS-tunneling exfiltration channel and the absence of installer consent.\n\n## Source: ossf-package-analysis (77fbceeb8527e33ef6a3b68c9238f3a25b9ccaf8e2023b1e12b2a95e3a0f274e)\nThe OpenSSF Package Analysis project identified 'dpg-media-7ehemel' @ 999.9.15 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n","affected":[{"package":{"name":"dpg-media-7ehemel","ecosystem":"npm"},"versions":["999.9.15"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"index.js","sha256":"9c5701633f4302a94b50625995679e2f5f0c3c681731dc5d59cbc5a11201b366","tlsh":"9012d75702f6243013e265682e8784c4776bd517378aebf0b94d47601fee26843b37ea"}],"package_integrity":[{"filename":"dpg-media-7ehemel-999.9.15.tgz","hashes":{"sha1":"318debc11da223778cceb9e472ada72a1c8c2d43","sha512_sri":"sha512-J/DoswxsQ5uPTz6OiOYY0JU+bMVnF1+COcG/ZDTua8a2HN206VbNtz4wUJBJkc+s4CMkfdCbJsGDmAiw966M5A=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/dpg-media-7ehemel/v/999.9.15"}],"database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-24T14:20:02.407784991Z","modified_time":"2026-08-24T14:00:56Z","sha256":"77fbceeb8527e33ef6a3b68c9238f3a25b9ccaf8e2023b1e12b2a95e3a0f274e","source":"ossf-package-analysis","versions":["999.9.15"]},{"id":"IN-MAL-2026-018625","import_time":"2026-08-24T16:49:13.179456506Z","modified_time":"2026-08-24T16:38:25Z","sha256":"4a904ad03d7041e21fe41a101c6a2db4a6aa3106f7b36394208bb4a5a39ee594","source":"amazon-inspector","versions":["999.9.15"]}]},"credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}数据来源:OpenSSF Malicious Packages · Apache-2.0