{"id":"MAL-2026-11151","summary":"Malicious code in text-line-parser (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (c7e51069873e7107964bf35c4ad5deace11fd5269366791475b18d0426902749)\nThe package advertises itself as a text/line parsing utility, but its shipped index.js contains only unrelated color-conversion stubs (hexToRgb/rgbToHsl). On `npm install`, postinstall.js executes a shell pipeline that collects hostname, user, cwd, `uname`, `/proc/1/cgroup`, `/.dockerenv`, the process tree, local IP addresses, `/etc/resolv.conf` nameservers, and probes Tencent Cloud and AWS IMDS cloud-metadata endpoints. It then dumps the full process environment (filtering only npm_* noise, so CI tokens, cloud credentials, and API keys are captured) together with GitHub Actions identifiers (GITHUB_REPOSITORY, GITHUB_ACTOR, GITHUB_RUN_ID, CI, RUNNER_NAME), base64-encodes the payload, and sends it via HTTP to the hardcoded Burp Collaborator subdomain pzs5w7ntzhsnepwk564lyfdci3oucl0a.oastify.com. The declared package purpose does not require any of this behavior; the mismatch between the advertised text-parsing role and the shipped reconnaissance/exfiltration code is consistent with a typosquat/decoy supply-chain attack.\n","modified":"2026-07-28T14:37:26.023453681Z","published":"2026-07-28T13:37:07Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-010924","import_time":"2026-07-28T14:19:59.315885441Z","modified_time":"2026-07-28T13:37:07Z","sha256":"c7e51069873e7107964bf35c4ad5deace11fd5269366791475b18d0426902749"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/text-line-parser/v/1.0.0"}],"affected":[{"package":{"name":"text-line-parser","ecosystem":"npm","purl":"pkg:npm/text-line-parser"},"versions":["1.0.0"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"path":"postinstall.js","sha256":"5826f6884581fbfa40d0793ff4c4b6f3b4e5e0a704bfd87bf7c4e3ec274b2ec9","tlsh":"8931fbf8b56ded72304dc5f8b75d14053846eaeb58e4ff74281b8875008e48420a9136"},{"tlsh":"68d05e105e229773b9c09bba2e176206b6610e5b1204fc2c67a75558878f27644ff219","path":"package.json","sha256":"22f7e7e084e30d9bda67d14a20714386c8ca4f3a10dbb922026ad7696b1e7fab"}],"package_integrity":[{"filename":"text-line-parser-1.0.0.tgz","hashes":{"sha512_sri":"sha512-e0bB283o8J1HtIWVEm9o9exu6pE3DOUluNV0zL0quiaWDsZuCNA9/Ex9mmc5442qCZiMXa9noo35F/gZhRuvUA==","sha1":"24d124610638206c28470bb03ddedf015bbed0f8"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/text-line-parser/MAL-2026-11151.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}