{"id":"MAL-2026-11069","summary":"Malicious code in clerk-next-fix-auth-protection (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (4fd8aaf2fc6ca964eed6950b6868486125905bacabe6b8bb1cbd581bb6a59f4c)\nclerk-next-fix-auth-protection@8.8.8 is a typosquat of Clerk/Next.js auth tooling that ships no functional code (declared main index.js is absent from the tarball). Both preinstall and postinstall lifecycle hooks in package.json run a plain-HTTP curl to http://u3ukeehm.requestrepo.com/depconf/clerk-next-fix-auth-protection/ with the installer's username (whoami), hostname, current working directory, and timestamp embedded in the query string. The beacon fires unconditionally on npm install, targets an anonymous requestrepo.com subdomain, and constitutes a dependency-confusion/typosquat reconnaissance probe that exfiltrates installer identity to an attacker-controlled endpoint.\n\n## Source: ossf-package-analysis (11ae257db932f3501d4f9168d9fb3c7abbdb1c6dad37f5bab183785662b3d9b6)\nThe OpenSSF Package Analysis project identified 'clerk-next-fix-auth-protection' @ 8.8.8 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package executes one or more commands associated with malicious behavior.\n","modified":"2026-08-04T23:04:56.476340306Z","published":"2026-07-24T21:48:05Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-07-27T01:42:44.34274726Z","modified_time":"2026-07-24T21:48:05Z","sha256":"11ae257db932f3501d4f9168d9fb3c7abbdb1c6dad37f5bab183785662b3d9b6","source":"ossf-package-analysis","versions":["8.8.8"]},{"import_time":"2026-07-27T01:42:44.241881516Z","modified_time":"2026-07-24T21:55:38Z","sha256":"237107ad75c2e23fe27919d8b194c3ce7b4048e31db18b7b2d280d4f1e0cf0e8","source":"ossf-package-analysis","versions":["7.7.7"]},{"import_time":"2026-08-04T22:29:59.650632994Z","modified_time":"2026-08-04T21:33:31Z","sha256":"4fd8aaf2fc6ca964eed6950b6868486125905bacabe6b8bb1cbd581bb6a59f4c","source":"amazon-inspector","versions":["8.8.8"],"id":"IN-MAL-2026-011107"},{"sha256":"99dc8073336435a1acd114bbe82de530edc986eaa41e0dc6f9596dc2d75ba085","source":"amazon-inspector","versions":["7.7.7"],"id":"IN-MAL-2026-011106","import_time":"2026-08-04T22:29:59.607309996Z","modified_time":"2026-08-04T21:33:18Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/clerk-next-fix-auth-protection/v/8.8.8"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/clerk-next-fix-auth-protection/v/7.7.7"}],"affected":[{"package":{"name":"clerk-next-fix-auth-protection","ecosystem":"npm","purl":"pkg:npm/clerk-next-fix-auth-protection"},"versions":["8.8.8","7.7.7"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"package.json","sha256":"49381df8803bcd4a725ff0d6343689155ad8340ec12ca4957cbeeb892acf2564","tlsh":"43f02b24b8207c237ec2465918958b0fba81e757469028265263ec4c68dc2f755b725f"}],"package_integrity":[{"filename":"clerk-next-fix-auth-protection-8.8.8.tgz","hashes":{"sha1":"a86946b97b1f2badd8628fc63845db2f79bea31c","sha512_sri":"sha512-jYTamCMDpSTNcOLb4LMpOuA2N4kIHcYIXyTkDc9eEbCLDF6iAWIqaWiuVsqaxDQiUiUFzZJjL8HUQGulRirK2A=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/clerk-next-fix-auth-protection/MAL-2026-11069.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}