{"id":"MAL-2025-6694","summary":"Malicious code in amdocs-auth-package (npm)","details":"The package communicates with a domain associated with malicious activity.\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (5d16664451db45f3a8b8da108a2b38785d0a7471480df169c57b38bccde640f7)\nPackage name mimics an Amdocs internal package (dependency-confusion lure). package.json declares `preinstall: node index.js`, so `npm install` auto-executes index.js. index.js collects host reconnaissance via Node's os module and child_process (hostname, platform, arch, homedir, username/uid/gid/shell, OS info, plus output of `whoami`, `id`, and `pwd`) and POSTs the JSON payload to a hardcoded Burp Collaborator subdomain at https://bet2pv7fumnp3hnz9u5oxggb329txjl8.oastify.com/detox56. No legitimate functionality is present; the sole install-time effect is reconnaissance exfiltration to an attacker-controlled out-of-band callback host.\n\n## Source: ossf-package-analysis (c756549e7fbf260738e6865ac35a33c132117c1e51d74abfe20fd5ab84cc5666)\nThe OpenSSF Package Analysis project identified 'amdocs-auth-package' @ 99.1.0 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n\n- The package executes one or more commands associated with malicious behavior.\n","modified":"2026-07-16T19:19:41.564214794Z","published":"2025-08-03T04:02:38Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-01-01T15:38:09.782860082Z","modified_time":"2026-01-01T15:31:13Z","versions":["99.1.0"],"source":"ossf-package-analysis","sha256":"c756549e7fbf260738e6865ac35a33c132117c1e51d74abfe20fd5ab84cc5666"},{"source":"amazon-inspector","sha256":"5d16664451db45f3a8b8da108a2b38785d0a7471480df169c57b38bccde640f7","import_time":"2026-07-16T18:54:00.367937807Z","id":"IN-MAL-2026-010707","modified_time":"2026-07-16T18:35:23Z","versions":["115.2.1"]},{"source":"amazon-inspector","sha256":"b2c4ca6b6c59796ce15d97e210e36506a9a56c6eaba6ab7695c1f887edd316a7","import_time":"2026-07-16T18:54:00.620570371Z","id":"IN-MAL-2026-010712","modified_time":"2026-07-16T18:36:13Z","versions":["114.2.1"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/amdocs-auth-package/v/115.2.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/amdocs-auth-package/v/114.2.1"}],"affected":[{"package":{"name":"amdocs-auth-package","ecosystem":"npm","purl":"pkg:npm/amdocs-auth-package"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.0.0"}]}],"versions":["99.1.0","115.2.1","114.2.1"],"database_specific":{"indicators":{"evidence_files":[{"sha256":"f8cf525c8b3ba0fe34058c9bfd621647bfd8506011519ed10c48067982e9579e","tlsh":"ac5152c519f659241ba7b8494a0f9402a327e0033549ee55bfcc8340af9837c9bf0bf6","path":"index.js"}],"package_integrity":[{"hashes":{"sha512_sri":"sha512-hP86wYA6d7R1tPOL7J1KYOGDEkQvzqNTirJNnG+oFfwd5QzptEMWHu4WQoqvIt638y6O36aoB6jElhxQR+NhNw==","sha1":"f4c97835b14e30f75e903f2722f67a7cb2f9f899"},"filename":"amdocs-auth-package-115.2.1.tgz"}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/amdocs-auth-package/MAL-2025-6694.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com","inspector-research@amazon.com"],"type":"FINDER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}