{"id":"MAL-2026-10952","summary":"Malicious code in @markscan/core (npm)","details":"The @markscan/core package was published to the npm registry by user 'jonothhu' (maintainer email bruemleveroger@gmail.com) as one of 19 packages in a dependency-confusion campaign targeting the 'markscan', 'akrai', and 'iphouse' namespaces, published in both unscoped and scoped (@scope/name) forms so that a misconfigured resolver installs the public lookalike instead of an intended private/internal dependency. Each package self-describes as an 'AUTHORIZED SECURITY RESEARCH CANARY' (static token PATHC-CANARY-2026, contact farouqsa@proton.me), but ships an unconsented install-time beacon and provides no legitimate functionality.\n\nThe package declares a postinstall hook (\"node postinstall.js\") that executes automatically on npm install. The bundled postinstall.js collects host reconnaissance - the package/canary name, the static token 'PATHC-CANARY-2026', an event label, a UTC timestamp, the Node.js version, the current working directory, the platform, and os.hostname() - and exfiltrates it via HTTPS POST to a hardcoded anonymous dead-drop at https://webhook.site/129cb2ee-ba08-4b3c-989c-270dc0030350 (the same collector across all 19 packages). Request errors are swallowed.\n\nThe self-attestation of 'authorized security research' present in the package metadata is unverifiable and does not change the disposition: the package performs unconsented telemetry collection and exfiltration at install time to an anonymous collector, matching the behavior of a dependency-confusion reconnaissance beacon. Install-time behavior and the shared collector endpoint were confirmed by static analysis of a sample spanning all three namespaces and both scoped and unscoped variants.","modified":"2026-07-23T07:50:22.076680766Z","published":"2026-07-20T00:00:00Z","database_specific":{"malicious-packages-origins":null},"references":[{"type":"WEB","url":"https://www.npmjs.com/package/@markscan/core"}],"affected":[{"package":{"name":"@markscan/core","ecosystem":"npm","purl":"pkg:npm/%40markscan/core"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"iocs":{"urls":["https://webhook.site/129cb2ee-ba08-4b3c-989c-270dc0030350"],"domains":["webhook.site"]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@markscan/core/MAL-2026-10952.json"}}],"schema_version":"1.7.5","credits":[{"name":"SafeDep","contact":["https://safedep.io"],"type":"FINDER"}]}