{"id":"MAL-2026-12355","summary":"Malicious code in com.db.dbk.ui-forms (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (c74649b28994f970d4972ffb8708378b355186eb729bf2e4c45d6acd16346e5d)\ncom.db.dbk.ui-forms@99.0.1 is a version-inflated package published to the public npm registry under a scope that resembles an internal namespace. Its package.json declares `preinstall: node index.js`, which runs automatically on `npm install`. index.js collects host identifiers (os.hostname(), os.platform(), os.userInfo(), homedir, network interfaces) and the output of shell commands (uname, id, whoami) via child_process, and enumerates process.env for keys matching /key|token|secret|pass|auth|cred|npm|ci|build|jenkins|github|gitlab|aws|azure/i. The collected payload is POSTed via https.request/http.request to the hardcoded interactsh callback host `ycwyyoimdcluajepubahl0tpb7943a2z4.oast.fun` at path `/dcf/\u003cpkg\u003e`, with a base64-chunked copy also emitted via DNS lookups to the same host. The package.json self-describes as a `dependency confusion proof of concept`; the installer-side behavior is exfiltration regardless of that framing.\n","modified":"2026-08-05T13:35:13.898271180Z","published":"2026-08-05T12:57:17Z","database_specific":{"malicious-packages-origins":[{"versions":["99.0.0"],"id":"IN-MAL-2026-014824","import_time":"2026-08-05T13:08:49.358634847Z","modified_time":"2026-08-05T12:57:34Z","sha256":"8c06da3e977cc6beaf2de938ad317573d53bbb6574a537e5f28e5f2addafbba5","source":"amazon-inspector"},{"import_time":"2026-08-05T13:08:49.13585634Z","modified_time":"2026-08-05T12:57:17Z","sha256":"c74649b28994f970d4972ffb8708378b355186eb729bf2e4c45d6acd16346e5d","source":"amazon-inspector","versions":["99.0.1"],"id":"IN-MAL-2026-014822"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/com.db.dbk.ui-forms/v/99.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/com.db.dbk.ui-forms/v/99.0.1"}],"affected":[{"package":{"name":"com.db.dbk.ui-forms","ecosystem":"npm","purl":"pkg:npm/com.db.dbk.ui-forms"},"versions":["99.0.0","99.0.1"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"hashes":{"sha512_sri":"sha512-ipU8euL04depqVMbH9F12m58r74199p87xuJmwOOKBhBnNbFfK/ouBFw2+AxjlGanj/9w60v7rn4ZoGTcEo3eA==","sha1":"49453367167b0df38a514b8866a5c099110396aa"},"filename":"com.db.dbk.ui-forms-99.0.0.tgz"}],"evidence_files":[{"path":"index.js","sha256":"2684afae7cee8ca5e83b9fe92cecd0060a6792e4e4527a981bd882e0f4cb8cc5","tlsh":"0f0110f0a1f462f03dbd98c0a8665b1512a3c6137986fce0f68802a45f8eaf885b24d5"},{"path":"package.json","sha256":"9191a57f8823320ba4587b4f7b65544c44d70b84dda07432a10aaf2a6c613bf1","tlsh":"0ef05c3c9d6090331ee045d069b5964a16778c2b4b09ac74eb53014c55abfe621bb29d"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/com.db.dbk.ui-forms/MAL-2026-12355.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}