{"id":"MAL-2026-13744","summary":"Malicious code in @dgn-src-click-to-pay-org/srcdcfreleasecert (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (6c203676b4cd54080189fef8d6740d09a1667f2ba0d939936ee46bd6dda4e15d)\nThe package's postinstall hook (scripts/check-env.js) executes on npm install and POSTs the package name/version along with the host's platform, architecture, and Node.js version to a hardcoded bare-IP endpoint at http://16-171-38-148.sslip.io:8080/api/install over plain HTTP. The package is published at version 999.0.1 — a sentinel value chosen to outrank legitimate internal versions during resolution — under a scoped organization name evoking a payments vendor (Discover/SRC click-to-pay), while the module body contains only trivial PAN/Luhn helpers. This is the canonical dependency-confusion reconnaissance shape: the squatted scope resolves inside a target build system and the postinstall beacon reports back which internal environments were successfully hijacked, enabling attacker follow-up against those hosts.\n","modified":"2026-08-11T19:00:11.538201181Z","published":"2026-08-11T18:50:11Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-11T18:52:01.394906528Z","modified_time":"2026-08-11T18:50:11Z","sha256":"6c203676b4cd54080189fef8d6740d09a1667f2ba0d939936ee46bd6dda4e15d","source":"amazon-inspector","versions":["999.0.1"],"id":"IN-MAL-2026-017386"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@dgn-src-click-to-pay-org/srcdcfreleasecert/v/999.0.1"}],"affected":[{"package":{"name":"@dgn-src-click-to-pay-org/srcdcfreleasecert","ecosystem":"npm","purl":"pkg:npm/%40dgn-src-click-to-pay-org/srcdcfreleasecert"},"versions":["999.0.1"],"database_specific":{"indicators":{"evidence_files":[{"path":"scripts/check-env.js","sha256":"46c5520d3525e4ab6700a4a5b958685cbe75a5e8f0eabee489179a63f4363e9f","tlsh":"9021b7c855fa9c311f5ae18e60eb590a127d5101351fd8b8b09d00412f93abc52f1fec"},{"path":"package.json","sha256":"d4be85316e5a6e6760644235515328f2adaf1bdf061086e343eb33e942e30625","tlsh":"68f055a8e8154c2324c5aa5b0c2742073620ce4b0651bd0d7b97618c479eb7b8eff16c"}],"package_integrity":[{"filename":"srcdcfreleasecert-999.0.1.tgz","hashes":{"sha1":"b9f988568613e2594d28d633a6cf90f7539cee1d","sha512_sri":"sha512-ltqK87qQfAlxsV8BjMeg0TXcNplNFSlJTEkKW3mk7b20wMmYoKZ+xt3kr3fy3kPoPu9OZYf0peSOMrF/HPMdBw=="}}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@dgn-src-click-to-pay-org/srcdcfreleasecert/MAL-2026-13744.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}