{"id":"MAL-2026-10080","summary":"Malicious code in webrix-docs (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (bec06de7c68db5cdd90e4b05be057a583f1a2318174916af07ed86d52a5011fc)\npackage.json declares `preinstall: node index.js`, which runs automatically on `npm install`. index.js collects host reconnaissance data — os.hostname(), os.userInfo() (username, uid, gid, homedir), process.platform, cwd, and the output of `whoami`/`id` spawned via child_process — and POSTs it as JSON to the hardcoded URL https://c7kfuaf25guwigaz6r03kxet0k6bu3is.oastify.com/detox56 (a Burp Collaborator / oastify.com out-of-band interaction subdomain). The package has an empty description and author, no library code, and a name that mimics the legitimate `webrix` UI library — consistent with a typosquat/dependency-confusion lure whose only purpose is the install-time beacon.\n","modified":"2026-07-09T16:32:05.078737603Z","published":"2026-07-09T15:45:45Z","database_specific":{"malicious-packages-origins":[{"sha256":"bec06de7c68db5cdd90e4b05be057a583f1a2318174916af07ed86d52a5011fc","source":"amazon-inspector","versions":["20.2.11"],"id":"IN-MAL-2026-009220","import_time":"2026-07-09T16:20:52.20436572Z","modified_time":"2026-07-09T15:45:45Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/webrix-docs/v/20.2.11"}],"affected":[{"package":{"name":"webrix-docs","ecosystem":"npm","purl":"pkg:npm/webrix-docs"},"versions":["20.2.11"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"sha256":"47f1b70eb518ccb31df256490ddd800165fe3f0d1657e4e6c0e7e7ec22e9adb2","tlsh":"bf5140c515f65a251ba7b8494a4f9012a327e0033509ee55bfcc8340af9937c97f0bf6","path":"index.js"},{"path":"package.json","sha256":"13c39b42b41a522b740c4dd07d087a740580d209cd625eb5e4df816f3a70cc4e","tlsh":"a8d0a7344d21953365c106660c2ba48773619f2f04047c0863df1c2c42de677a8ff30d"}],"package_integrity":[{"filename":"webrix-docs-20.2.11.tgz","hashes":{"sha1":"609b5c3ba7e9bd46c165e77c015e5819a51c2c1c","sha512_sri":"sha512-rZx3z0xauZf2TJPjkHmvurgRhEzdgtJYN3kpEAU+jKAo9M8k1U9fk58EYWPII4WKIXFZf5C3aIrP8mx00tDJOw=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/webrix-docs/MAL-2026-10080.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}