{"id":"MAL-2026-10081","summary":"Malicious code in webrix-docs1 (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (20cdefe1415c5b5245f36b10ea0de9033433b479768c2cc785ad2742b9433fce)\nThe package declares a preinstall hook (`node index.js`) that fires automatically on `npm install`. The script requires `child_process`, `os`, `https`, and `http`, collects hostname, platform, arch, username/uid/gid, shell, home directory, CPU/memory stats, cwd, and the output of `whoami`/`id`, then POSTs the JSON payload to a hardcoded Burp Collaborator (oastify.com) subdomain at `https://c7kfuaf25guwigaz6r03kxet0k6bu3is.oastify.com/detox56`. The package has an empty description and empty author, presents no advertised functionality, and its name mimics the `webrix` project — consistent with dependency-confusion/typosquat recon. Installing the package directly leaks installer host and user identifiers to an attacker-controlled OAST endpoint.\n","modified":"2026-07-09T16:32:05.703993149Z","published":"2026-07-09T15:45:53Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-07-09T15:45:53Z","sha256":"20cdefe1415c5b5245f36b10ea0de9033433b479768c2cc785ad2742b9433fce","source":"amazon-inspector","versions":["10.2.11"],"id":"IN-MAL-2026-009221","import_time":"2026-07-09T16:20:52.286618381Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/webrix-docs1/v/10.2.11"}],"affected":[{"package":{"name":"webrix-docs1","ecosystem":"npm","purl":"pkg:npm/webrix-docs1"},"versions":["10.2.11"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"sha256":"47f1b70eb518ccb31df256490ddd800165fe3f0d1657e4e6c0e7e7ec22e9adb2","tlsh":"bf5140c515f65a251ba7b8494a4f9012a327e0033509ee55bfcc8340af9937c97f0bf6","path":"index.js"},{"sha256":"df189ce49e0879e02a7fe10e2538abddbcc3bb6379229ebdf6c82071166b32ea","tlsh":"ccd0a7304e21553365c106620c2ba59772619f2f04157c0863df1c2c82de67798ff34e","path":"package.json"}],"package_integrity":[{"filename":"webrix-docs1-10.2.11.tgz","hashes":{"sha512_sri":"sha512-IhE1D8dgie8/RECERBcZYEwmmrvn43wo6MJ6jcq7QhQt/ROEYfWKqQyhq12d8NHMQ9IwEi+pSp3T1Ya+1sI2Nw==","sha1":"eb0ea97db60c29957ce9db08f8132fe85b63daba"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/webrix-docs1/MAL-2026-10081.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}