{"id":"MAL-2026-12506","summary":"Malicious code in @latlongid/location (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (134cf39570bebc6b10043353b9194b41e30da9b0f55147501ccc060bb32c7e8e)\n@latlongid/location@1.0.1 declares `postinstall: node index.js` in package.json, so `index.js` runs automatically on every `npm install`. That script hex-encodes the installer's `os.hostname()` and embeds it as a subdomain of `dns.gl0b.xyz`, then invokes `dns.lookup` on the constructed name (e.g. `2d5bccee-...-h\u003chex(hostname)\u003e.\u003crand\u003e.dns.gl0b.xyz`). The DNS query name itself carries the host identifier off the machine, so exfiltration succeeds regardless of resolution result. The scoped name and generic 'internal utility' metadata are consistent with a dependency-confusion reconnaissance beacon designed to enumerate reachable internal build environments.\n","modified":"2026-08-05T14:35:01.754392495Z","published":"2026-08-05T13:13:42Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-05T14:19:44.321242226Z","modified_time":"2026-08-05T13:13:42Z","sha256":"134cf39570bebc6b10043353b9194b41e30da9b0f55147501ccc060bb32c7e8e","source":"amazon-inspector","versions":["1.0.1"],"id":"IN-MAL-2026-014933"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@latlongid/location/v/1.0.1"}],"affected":[{"package":{"name":"@latlongid/location","ecosystem":"npm","purl":"pkg:npm/%40latlongid/location"},"versions":["1.0.1"],"database_specific":{"indicators":{"evidence_files":[{"sha256":"6ebd99dd4a91795c58356f63e86a21673d7325afb55c32492e7b499ac8c816cb","tlsh":"bee02bc81af0f638227011c1f199ef1327c3dba43584c495c94f1ab745d99b24e72cd6","path":"index.js"}],"package_integrity":[{"hashes":{"sha1":"c206ab035f72275aab165134ed71747f4f353c47","sha512_sri":"sha512-qkQjrfAvF+1Upab7USKg7FpyTYURpXyppj7VhlaAo9C8zndBYL+Npz2IF/VwZp/Gd9t50rX94SfUIOflC4EKrg=="},"filename":"location-1.0.1.tgz"}]},"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@latlongid/location/MAL-2026-12506.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}