{"id":"MAL-2026-13435","summary":"Malicious code in @united-airlines-org/atmos-design-system (npm)","details":"The package @united-airlines-org/atmos-design-system contains a malicious `preinstall` script in its package.json that runs automatically during installation. The script executes `curl` to send the machine's hostname, obtained via `uname -n` and base64-encoded, to the attacker-controlled endpoint `https://bxss.boll-sec.de/hostname_\u003cbase64-hostname\u003e`. This exfiltrates host reconnaissance data to a remote server. All versions of the package are malicious.\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (5683e7389b9b288024f2c9827c3649d7b291996625265f6365535121fc1f431a)\nPackage @united-airlines-org/atmos-design-system@41.0.0 ships no library code — only a package.json whose `preinstall` script runs `/usr/bin/curl` to https://bxss.boll-sec.de/callb with base64-encoded values of `uname -n`, `ls` of the current directory, and `whoami` as query parameters. This fires automatically on `npm install`, sending the installer's hostname, working-directory listing, and username to an external, non-first-party host. The scope name resembles an internal United Airlines organization and the package contains no functional code beyond the beacon, matching the dependency-confusion pattern in which resolution of an internal package name pulls in an attacker-published public artifact.\n","modified":"2026-08-07T00:04:57.458212426Z","published":"2026-08-06T00:00:00Z","database_specific":{"iocs":{"domains":["bxss.boll-sec.de"]},"malicious-packages-origins":[{"modified_time":"2026-08-06T19:12:12Z","sha256":"5683e7389b9b288024f2c9827c3649d7b291996625265f6365535121fc1f431a","source":"amazon-inspector","versions":["41.0.0"],"id":"IN-MAL-2026-016750","import_time":"2026-08-06T23:25:07.441082535Z"},{"source":"amazon-inspector","versions":["40.0.0"],"id":"IN-MAL-2026-016751","import_time":"2026-08-06T23:25:07.500169229Z","modified_time":"2026-08-06T19:12:19Z","sha256":"6b82e32ac4430e26041e8e3df065620ea4bb58bc1a2a7c8bf1933e1760a77417"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@united-airlines-org/atmos-design-system/v/41.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@united-airlines-org/atmos-design-system/v/40.0.0"}],"affected":[{"package":{"name":"@united-airlines-org/atmos-design-system","ecosystem":"npm","purl":"pkg:npm/%40united-airlines-org/atmos-design-system"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"versions":["41.0.0","40.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"tlsh":"e1f0ec70d5591473dbc18e5708045a66a1905f1f09407c5597cb5178d1ce3f374f6b1c","path":"package.json","sha256":"92e2ab0aa04991f6c31275498e8eab4907ffdff8b82abaffe05388af1c6e73f7"}],"package_integrity":[{"filename":"atmos-design-system-41.0.0.tgz","hashes":{"sha512_sri":"sha512-L4FGAOJB1S06i0P3v01li0WaBlYyFHnMufGadaw/tWzLKMTzgh/2k+Q+WJrWeIsSpNdj1t2fvxUvAAGjzQtH7g==","sha1":"0925fd318c068b4dab437018e8ae9c393e655444"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@united-airlines-org/atmos-design-system/MAL-2026-13435.json"}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"SafeDep","contact":["https://safedep.io"],"type":"FINDER"}]}