{"id":"MAL-2026-10739","summary":"Malicious code in mw-server-util (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (1401412848e55e1515db44b1f513ad6e39628f06c24c3b057a08448c9e8ee44c)\nmw-server-util 2.0.1 ships a postinstall hook that runs mw.js, which reads os.hostname() and os.userInfo() and issues an HTTPS GET to a hardcoded Burp Collaborator subdomain gdx35zc4m7hymba6asotmwhd349vxlla.oastify.com, transmitting the installer's hostname, username, package name, and a timestamp on `npm install`. The destination is an attacker-controlled OAST callback typical of dependency-confusion beacons; the fetch fires automatically as a lifecycle side effect with no relation to any documented package purpose.\n","modified":"2026-07-16T19:19:49.058547661Z","published":"2026-07-16T18:37:57Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-07-16T18:54:01.342376763Z","modified_time":"2026-07-16T18:38:05Z","sha256":"1401412848e55e1515db44b1f513ad6e39628f06c24c3b057a08448c9e8ee44c","source":"amazon-inspector","versions":["2.0.1"],"id":"IN-MAL-2026-010724"},{"sha256":"9827776af0bcdd4df831ab5e5d567d67f18436f256a21b3d528dac3506685261","source":"amazon-inspector","versions":["2.0.0"],"id":"IN-MAL-2026-010723","import_time":"2026-07-16T18:54:01.269721295Z","modified_time":"2026-07-16T18:37:57Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/mw-server-util/v/2.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/mw-server-util/v/2.0.0"}],"affected":[{"package":{"name":"mw-server-util","ecosystem":"npm","purl":"pkg:npm/mw-server-util"},"versions":["2.0.1","2.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/mw-server-util/MAL-2026-10739.json","indicators":{"package_integrity":[{"filename":"mw-server-util-2.0.1.tgz","hashes":{"sha512_sri":"sha512-8n/p/DpIEcHMuKqwuH0bkeAA5YmBE1vre5hbpSKHvJ7W2nHSyKqobWqMcnPiJsmy1fqqEaB+tZ2f3+LR1PI7Pw==","sha1":"a5b50b7deb027cc0e26822bd6f8818cc952c495d"}}],"evidence_files":[{"sha256":"2a5c4745085cfadf4fc58cf8d3cd04420447009715c9683f77467c09a38df4e8","tlsh":"19e0abec02e0e2752de171d0e8209c88a2bbe5823d13b0e7cb8c30b5d241ce14db3790","path":"mw.js"}]}}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}