{"id":"MAL-2026-11055","summary":"Malicious code in fundraiserservicepp (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (6356b654b692d4c1222f3dc31dcfad683a6e193a41484d3c617c7c8d52db2313)\nOn npm install, the package's preinstall lifecycle executes index.js which collects os.hostname(), os.platform(), and os.arch() and POSTs them as JSON over HTTPS to the hardcoded subdomain rpke7za0zz1pwj9fz5058j0y5pbgz82wr.oastify.com — a Burp Collaborator out-of-band collector. The package provides no advertised functionality beyond this beacon and matches the dependency-confusion probe shape, with installer host identifiers leaving the machine automatically to a third-party OOB endpoint the installer did not opt into.\n\n## Source: ossf-package-analysis (cefb4588a67439c112176df4b9af71d40a1e2a12e0bf81ef200affa79e0cb0e0)\nThe OpenSSF Package Analysis project identified 'fundraiserservicepp' @ 1.5.0 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n","modified":"2026-08-05T14:37:12.465222784Z","published":"2026-07-25T08:20:10Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-07-25T08:48:46.228106611Z","modified_time":"2026-07-25T08:20:10Z","sha256":"cefb4588a67439c112176df4b9af71d40a1e2a12e0bf81ef200affa79e0cb0e0","source":"ossf-package-analysis","versions":["1.5.0"]},{"import_time":"2026-08-04T22:29:59.776889036Z","modified_time":"2026-08-04T21:33:55Z","sha256":"8ee5547a9548aa8d9a79a6b9b8a8ded3a27c1164c780957ce31645c39253ec04","source":"amazon-inspector","versions":["1.5.0"],"id":"IN-MAL-2026-011110"},{"import_time":"2026-08-05T14:19:44.03846264Z","modified_time":"2026-08-05T13:13:15Z","sha256":"6356b654b692d4c1222f3dc31dcfad683a6e193a41484d3c617c7c8d52db2313","source":"amazon-inspector","versions":["1.7.0"],"id":"IN-MAL-2026-014930"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/fundraiserservicepp/v/1.5.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/fundraiserservicepp/v/1.7.0"}],"affected":[{"package":{"name":"fundraiserservicepp","ecosystem":"npm","purl":"pkg:npm/fundraiserservicepp"},"versions":["1.5.0","1.7.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/fundraiserservicepp/MAL-2026-11055.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"hashes":{"sha1":"02a486b9e8b08ad9b5a12531fe2b262da3b91fce","sha512_sri":"sha512-CoqIIY28/HMN9qbq2JPdPBsjhxsn/bQuvo8yWd35Or2pk1ki1ICKtPPQCIDFv/rQKcWPR3547SsJAuTYApvKhw=="},"filename":"fundraiserservicepp-1.5.0.tgz"}],"evidence_files":[{"path":"index.js","sha256":"74063af355f696dfb4eb86d02a3709104e390034ed470e9bed162d9711e6e5f2","tlsh":"79e05cf0e1a59b705bb586d4a0fa9401c232ea737807b8e45fc8026617cddf800715e8"}]}}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}