MAL-2026-14434Malicious code in openai-pr-reviewer (npm)
| Ecosystem | Package | Version |
|---|---|---|
| npm | openai-pr-reviewer | 1.0.0 |
{"modified":"2026-08-24T16:45:53Z","published":"2026-08-24T16:45:53Z","schema_version":"1.7.4","id":"MAL-2026-14434","summary":"Malicious code in openai-pr-reviewer (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (3553acd3c5abc3f71b55740c4b06b2eb278f81bb678c55211f2287a498b60b61)\nThe package's preinstall hook runs index.js, which collects the installer's hostname, username, home directory, DNS servers, current working directory, package.json contents, and the contents of /etc/passwd and /etc/hosts, then POSTs them over HTTPS to the hardcoded Burp Collaborator subdomain vjib8dmg59zuxwwymzboy0ymhdn4bvzk.oastify.com. Execution is automatic on npm install via the preinstall lifecycle script, with no user interaction required.\n","affected":[{"package":{"ecosystem":"npm","name":"openai-pr-reviewer"},"versions":["1.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"index.js","sha256":"feed42c06b99af3621b40e246faa185aec35858aa86a9adc0d37fda581411e88","tlsh":"8f41139552c917330dd210c0aa0c70802359fa77715999d076cf4296af869f8b7316f3"}],"package_integrity":[{"filename":"openai-pr-reviewer-1.0.0.tgz","hashes":{"sha1":"7f41f77773f322c5df82d9c6c18da19dad8b8171","sha512_sri":"sha512-vqTvdzE/83GJuxWMw2IQ9cYNSLcr0XHkVdJrIU0+/qEw0yX4lwt4PSM9wkN9/e9NWj5ezWmtz0GxmYtryOx82w=="}}]}}}],"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/openai-pr-reviewer/v/1.0.0"}],"credits":[{"name":"Amazon Inspector","type":"FINDER","contact":["inspector-research@amazon.com"]}],"database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-018649","import_time":"2026-08-24T16:49:14.895869263Z","modified_time":"2026-08-24T16:45:53Z","sha256":"3553acd3c5abc3f71b55740c4b06b2eb278f81bb678c55211f2287a498b60b61","source":"amazon-inspector","versions":["1.0.0"]}]}}数据来源:OpenSSF Malicious Packages · Apache-2.0