{"id":"MAL-2026-12512","summary":"Malicious code in appsignal (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (ff26e8c679b4035612af78043157ee418aac37aab4eebc5ba54a6e60f204e95c)\nPackage name `appsignal` shadows the legitimate `@appsignal/*` scope and is published at version `9999.0.0`, a version-number pattern used to outrank private/internal dependencies during resolution. A `preinstall` script runs automatically on `npm install` and issues an HTTP GET to the hardcoded bare-IP endpoint `http://75.119.137.232:31337/depconfuse`, carrying the installer's `os.hostname()`, `os.userInfo().username`, `process.cwd()`, `npm_config_registry`, and CI repository-slug environment variables (`GITHUB_REPOSITORY`, `CI_PROJECT_PATH`, `BUILD_REPOSITORY_NAME`, `BITBUCKET_REPO_FULL_NAME`, `TRAVIS_REPO_SLUG`, `DRONE_REPO`, `BUILDKITE_PIPELINE_SLUG`, `CIRCLE_PROJECT_REPONAME`, `JOB_NAME`) as query parameters. The endpoint path `/depconfuse`, the bare-IP destination, the `9999.0.0` version, and the shadowing of an established scope indicate a dependency-confusion reconnaissance probe designed to identify internal build systems that resolve the public name over an intended private package.\n","modified":"2026-08-05T14:35:12.943667125Z","published":"2026-08-05T13:09:30Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-08-05T13:09:30Z","sha256":"ff26e8c679b4035612af78043157ee418aac37aab4eebc5ba54a6e60f204e95c","source":"amazon-inspector","versions":["9999.0.0"],"id":"IN-MAL-2026-014905","import_time":"2026-08-05T14:19:41.699949668Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/appsignal/v/9999.0.0"}],"affected":[{"package":{"name":"appsignal","ecosystem":"npm","purl":"pkg:npm/appsignal"},"versions":["9999.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"tlsh":"ea119eb9c68c0c340dc2178479686c1eb8fbe29133c294917f2d71d26bb22b046b75bd","path":"callback.js","sha256":"b754deb2c216bd803daae10124ea11ade36922f50248c8b1be8fa920c4052413"},{"sha256":"9572b615b4d4c3ce120480c3f28e8ba869607a68c904df7e0f2a2b7e39f82187","tlsh":"63d0a730da2358632cd8efd30c2a554612768e3b0548784a278b901d55a967719ff79e","path":"package.json"}],"package_integrity":[{"filename":"appsignal-9999.0.0.tgz","hashes":{"sha1":"f49a1d79d787327c51643ee53489a19b60aa75c4","sha512_sri":"sha512-LxaYThS1LZyKSBUUPdIUvrPui8dcD5RA8V0MjvL7U59w9KzOPP911s3uP9LyB7ieTw0SnYRA+AgQZzzIwKbu5Q=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/appsignal/MAL-2026-12512.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}