{"id":"MAL-2026-10403","summary":"Malicious code in @iana-rzms/bff-sdk (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (b7adbad0c719aec3345c5aa16b3435e8621f4a81b5a0e0cf0e0d979509e5d21f)\nPackage published to the public @iana-rzms scope as a dependency-confusion squat targeting an internal ICANN namespace. The preinstall lifecycle script runs automatically on npm install and collects the installer's hostname, OS username, and current working directory, base64-encodes them, and transmits them via HTTPS (port 443), HTTP (port 80), and DNS lookup to the hardcoded external host k4pzh6vg78iub3vxqhmml2q8wz2qqge5.oastify.com (a Burp Collaborator subdomain). The self-described 'authorized PoC' framing in the README does not change installer-side impact: any build that resolves @iana-rzms/bff-sdk from the public registry executes attacker/researcher-controlled code at install time and leaks host identity to a non-first-party collector.\n","modified":"2026-07-13T07:47:06.042483212Z","published":"2026-07-13T05:58:14Z","database_specific":{"malicious-packages-origins":[{"versions":["1.0.0"],"id":"IN-MAL-2026-009802","import_time":"2026-07-13T07:40:09.767603398Z","modified_time":"2026-07-13T05:58:14Z","sha256":"b7adbad0c719aec3345c5aa16b3435e8621f4a81b5a0e0cf0e0d979509e5d21f","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@iana-rzms/bff-sdk/v/1.0.0"}],"affected":[{"package":{"name":"@iana-rzms/bff-sdk","ecosystem":"npm","purl":"pkg:npm/%40iana-rzms/bff-sdk"},"versions":["1.0.0"],"database_specific":{"indicators":{"evidence_files":[{"tlsh":"bc51c5bf44f0511005f371e1cb6f7268936bf0028f96ca88b4ade218af29a280122df5","path":"preinstall.js","sha256":"66c65ba997c6f137c332031715fd5ac99bca238539300d3c3561856d376a46d3"},{"sha256":"c37932a6e3e555dad0fa3afbb20d4389d1ae83e0dac55586eef25a65dc2a2106","tlsh":"d6f0ac350412a93324d2bbe20d6f691266b758fa1028390d56db002cc69eb6b47bf63f","path":"package.json"}],"package_integrity":[{"hashes":{"sha1":"8b3adfce8f176427bd4e4874da1982de694ba820","sha512_sri":"sha512-6Diifi8G8QWzPJ7z62zPWTrCX2jLRHIHIhWz0YPWajDrMsqsT/J+89fJ/Gf4sQAR0llVK77vpjFXnalUPNK4hQ=="},"filename":"bff-sdk-1.0.0.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@iana-rzms/bff-sdk/MAL-2026-10403.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}