{"id":"MAL-2024-1783","summary":"Malicious code in auth0.net (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (299295a8f62b96e6336a60ce85d2212185bf0cf424cc548d8bca9f0b14ed85c1)\nOn `npm install`, package.json's `preinstall` (and `preupdate`/`test`) hook runs `nslookup bkxajsfkvlurhaoeotqbqf3fg2sitbxll.oast.fun`. The destination `oast.fun` is the Project Discovery interactsh out-of-band callback service used to confirm code execution on victim hosts via a unique DNS subdomain. Firing automatically on install leaks the installer's existence and the corporate DNS resolver's egress IP to an attacker-controlled nameserver, with the unique subdomain serving as a per-victim correlation token. The package itself is hollow — `index.js` is empty, `description` is the placeholder 'Internal package', and `author` is 'Team' — and the package name `auth0.net` impersonates the Auth0 brand, consistent with a dependency-confusion attempt against an internal Auth0/.NET package name. The DNS beacon is the recon stage of that attack: the operator learns which organizations have misconfigured their registry resolution to pull this public package instead of an internal one, enabling targeted follow-on compromise.\n","modified":"2026-06-12T20:01:47.137757124Z","published":"2024-06-25T12:28:41Z","database_specific":{"malicious-packages-origins":[{"versions":["7.22.1"],"source":"reversing-labs","sha256":"31fb618f0bf6bb37e60f2a94d7ae0fb90ca439b8e141db9520a006242a335b55","import_time":"2024-06-28T02:41:58.280270208Z","id":"RLMA-2024-00377","modified_time":"2024-06-25T12:28:41Z"},{"id":"RLUA-2024-06178","modified_time":"2024-10-16T12:32:48Z","source":"reversing-labs","sha256":"a033bb29ca10ee2dc795b9b881533ca73ab35ca29f4f421f7871a6057ac58ecf","import_time":"2024-10-24T00:57:33.083069669Z"},{"sha256":"299295a8f62b96e6336a60ce85d2212185bf0cf424cc548d8bca9f0b14ed85c1","import_time":"2026-06-12T19:43:58.081815234Z","id":"IN-MAL-2026-006011","modified_time":"2026-06-12T19:07:20Z","versions":["39.1.0"],"source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/auth0.net/v/39.1.0"}],"affected":[{"package":{"name":"auth0.net","ecosystem":"npm","purl":"pkg:npm/auth0.net"},"versions":["7.22.1","39.1.0"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"path":"package.json","sha256":"4f2814c71c35935d40e487c11fa11c8aeac4367a61a85e8d9301ba6c3b6ebb7b","tlsh":"3ae09b268d51ec731ff006eb6566050671a3ee1a40218eca74f6860ce29b7d39c27614"}],"package_integrity":[{"hashes":{"sha1":"e03c15154a7206bd83e5a088f1c14c5e5e9c07b9","sha512_sri":"sha512-QgWbEunF/eyYm24C4hyUQj1IOwfh0UiG+Sr6DsrkB9xkLjdm9uAEVs6HiK8pPb/xpfHA1gwcEXYGAf0/QKyZlA=="},"filename":"auth0.net-39.1.0.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/auth0.net/MAL-2024-1783.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}