{"id":"MAL-2026-12809","summary":"Malicious code in technical-challenge (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (6921f72a1b4fbaaba87fcbe3cb30137815e7e2bb932ffa794acd0010b8954c5f)\npackage.json declares `preinstall: node index.js`, causing index.js to run automatically on `npm install`. The script collects installer-side data — hostname, username, home directory, DNS server list, current working directory, package.json contents, and the contents of /etc/passwd and /etc/hosts — and HTTPS-POSTs it to a hardcoded Burp Collaborator subdomain at 5z5h9l8e7cktx1ihl6usn4zgb7h15rtg.oastify.com. The exfiltration fires unconditionally on install with no user interaction.\n","modified":"2026-08-05T14:37:24.277682674Z","published":"2026-08-05T13:14:00Z","database_specific":{"malicious-packages-origins":[{"sha256":"6921f72a1b4fbaaba87fcbe3cb30137815e7e2bb932ffa794acd0010b8954c5f","source":"amazon-inspector","versions":["1.0.1"],"id":"IN-MAL-2026-014935","import_time":"2026-08-05T14:19:44.502431233Z","modified_time":"2026-08-05T13:14:00Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/technical-challenge/v/1.0.1"}],"affected":[{"package":{"name":"technical-challenge","ecosystem":"npm","purl":"pkg:npm/technical-challenge"},"versions":["1.0.1"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"sha256":"63838de40d41b7dba0546dc04db004c973479c0c6c0b54000cef45e42f1c9b42","tlsh":"cb41f195a2d917330de210c06a0c70852399fa777159e99077cf4296af869f8b7326f3","path":"index.js"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/technical-challenge/MAL-2026-12809.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}