{"id":"MAL-2026-11430","summary":"Malicious code in list-issue-predecessor-dependencies-block (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (bbd4d4e3aa51ec1a7ebc0a0d4f728698503432546f139f67998849f8fff9b614)\nnpm package list-issue-predecessor-dependencies-block@99.0.0 auto-executes index.js from three lifecycle hooks (preinstall, install, postinstall) on npm install. The script collects installer identity and environment reconnaissance — os.hostname(), os.platform(), username, current working directory, output of shell commands (whoami, id, hostname -I via child_process), CI environment variables (GITHUB_*, GITLAB_*, JENKINS_*, etc.), AWS/GCP/Azure/Kubernetes cloud-metadata indicators, enumerated names of environment variables matching /KEY|SECRET|TOKEN|PASS|CRED|AUTH|API_|PRIVATE/i, and a boolean flag for the presence of NPM_TOKEN / NODE_AUTH_TOKEN — and exfiltrates it to the hardcoded Interactsh collaborator qtmetsrtvaujwklywbgw2wihc2lebzu0n.oast.fun via DNS lookups (dns.resolve of labeled subdomains), HTTPS POST to /depconf, and HTTP POST. The high version number (99.0.0) and generic internal-sounding package name are the standard dependency-confusion shape used to override private registry packages with a public squat.\n\n## Source: ossf-package-analysis (0f74d699bfc5fcf83c6f2864f93ecd41d3d9f8613f45f6bfb3b6dd5eeb7a880e)\nThe OpenSSF Package Analysis project identified 'list-issue-predecessor-dependencies-block' @ 99.0.0 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n\n- The package executes one or more commands associated with malicious behavior.\n","modified":"2026-08-04T22:05:08.835232726Z","published":"2026-08-02T19:04:25Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-02T19:31:07.083609961Z","modified_time":"2026-08-02T19:04:25Z","sha256":"0f74d699bfc5fcf83c6f2864f93ecd41d3d9f8613f45f6bfb3b6dd5eeb7a880e","source":"ossf-package-analysis","versions":["99.0.0"]},{"import_time":"2026-08-04T21:33:16.590765945Z","modified_time":"2026-08-04T21:31:46Z","sha256":"bbd4d4e3aa51ec1a7ebc0a0d4f728698503432546f139f67998849f8fff9b614","source":"amazon-inspector","versions":["99.0.0"],"id":"IN-MAL-2026-011095"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/list-issue-predecessor-dependencies-block/v/99.0.0"}],"affected":[{"package":{"name":"list-issue-predecessor-dependencies-block","ecosystem":"npm","purl":"pkg:npm/list-issue-predecessor-dependencies-block"},"versions":["99.0.0"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"sha256":"309ba9e59f80bbda4cc0c4f3d09c2eeee9890b57c40e724c81b937bb3e108502","tlsh":"937186d6a7fe0a2255e373e0309b081274abd1276345f4f0b55650293fbd62542b39fe","path":"index.js"},{"tlsh":"b1e020746c15553325f502d5a675940964b18d175144346495d2008ce3af776c07f34e","path":"package.json","sha256":"4a571ef812c3d7d6879cd89584766c20f450c5b1f156ca7fd5825fbbc9252a9d"}],"package_integrity":[{"filename":"list-issue-predecessor-dependencies-block-99.0.0.tgz","hashes":{"sha1":"b4f7f998cdbd6ecbaec68423d775db1b6b90f0be","sha512_sri":"sha512-26Ez1VrYcWuoeBIXEn1hhtBGMhD8X1ZKj6KJ1QJ85nVyfdk3KG3Cxj/3lOuDFDSCZ4/AeDO4XfjR3cjxo7fMKg=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/list-issue-predecessor-dependencies-block/MAL-2026-11430.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}