{"id":"MAL-2026-12795","summary":"Malicious code in knowledge-grader (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (74d01af74706eee07fb8ed306ec3b830641f63b4c055d605026edff65fd11c8f)\nThe package's preinstall hook runs index.js, which collects hostname, username, home directory, DNS servers, package path, and the contents of /etc/passwd and /etc/hosts, then HTTPS-POSTs the JSON payload to the hardcoded Burp Collaborator subdomain tebdjgz4guem6t74pf6iyowyjppgd71w.oastify.com. This fires automatically on npm install with no user interaction.\n","modified":"2026-08-05T14:37:14.942382670Z","published":"2026-08-05T13:15:58Z","database_specific":{"malicious-packages-origins":[{"versions":["1.0.1"],"id":"IN-MAL-2026-014949","import_time":"2026-08-05T14:19:45.855909974Z","modified_time":"2026-08-05T13:15:58Z","sha256":"74d01af74706eee07fb8ed306ec3b830641f63b4c055d605026edff65fd11c8f","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/knowledge-grader/v/1.0.1"}],"affected":[{"package":{"name":"knowledge-grader","ecosystem":"npm","purl":"pkg:npm/knowledge-grader"},"versions":["1.0.1"],"database_specific":{"indicators":{"evidence_files":[{"sha256":"71d15307a0ce84833c8ba1ee495bac88d5ad4c00592e6f0b11464423e1b31fa2","tlsh":"0041139592c917330dd210c0660c70802359fa767159a9d076cf42969f869f8b7226f3","path":"index.js"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/knowledge-grader/MAL-2026-12795.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}]}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}