{"id":"MAL-2026-13448","summary":"Malicious code in lib-frontsga (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (53a65c44cfdcbc89df47508f3f87fcab836f1fa2f4adf2298ecfb47cd6088038)\nPackage name 'lib-frontsga' published to the public npm registry at version 9.999.999 targets an internal package name via dependency-confusion resolution. A preinstall/postinstall lifecycle script (poc.js) runs on npm install and collects host identifiers (hostname, username, cwd, Node version) together with CI/build attribution (GITHUB_REPOSITORY, GITHUB_REPOSITORY_OWNER, GITHUB_ACTOR, GITHUB_RUN_ID, GITHUB_WORKFLOW, npm_config_registry, RUNNER_NAME, AWS_REGION, and Azure/Jenkins/GitLab identifiers). The collected data is transmitted to a hardcoded Interactsh callback subdomain via DNS queries and HTTP/HTTPS POST to votspfykpbaortacnitltze3m5k5swzg6.oast.fun. Any organization that internally uses this name without a scoped/internal registry pin will resolve this public copy and execute the install-time beacon, disclosing internal build-environment fingerprints to a third-party out-of-band server.\n","modified":"2026-08-06T23:50:15.149735906Z","published":"2026-08-06T16:22:49Z","database_specific":{"malicious-packages-origins":[{"versions":["9.999.999"],"id":"IN-MAL-2026-016683","import_time":"2026-08-06T18:09:05.705844181Z","modified_time":"2026-08-06T16:22:49Z","sha256":"53a65c44cfdcbc89df47508f3f87fcab836f1fa2f4adf2298ecfb47cd6088038","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/lib-frontsga/v/9.999.999"}],"affected":[{"package":{"name":"lib-frontsga","ecosystem":"npm","purl":"pkg:npm/lib-frontsga"},"versions":["9.999.999"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/lib-frontsga/MAL-2026-13448.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"sha256":"dc75559df6785b501e3cda4d7c460c75afa17d32571bbccbc753b54fc2b21bf8","tlsh":"b8b1b86b08d905211bf3a76a546f115774f7d2fe0586f7f4f00d435a0be82e8023a9ba","path":"poc.js"},{"sha256":"6aa32460fe6b17d7b2c701b9f5a891698dc7aa098c20b4a477d555cc68ed73f3","tlsh":"e70125a04540923319f102dd0c70a24e7831c93fd60ab51a77a9015cd38dafa42bb11e","path":"package.json"}],"package_integrity":[{"filename":"lib-frontsga-9.999.999.tgz","hashes":{"sha1":"ad79683a5788dd1cb564480942ecf0ac768e6ae6","sha512_sri":"sha512-273KNsKqs91a97jnChNQJ8BRSrvkslAc/Z9Q8PsRKIgx/6F3m/BHMeOfZAycIROauZ8iPvFuF5JFCgtsekHBHA=="}}]}}}],"schema_version":"1.8.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}