{"id":"MAL-2026-15561","summary":"Malicious code in techportal (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (2d947d5b4ddaa0ea6a25488fb5b5a66b3afc5c8f56d5ac38fb2e95e4b23242f3)\npackage.json declares a preinstall hook (`node beacon.js`) that fires automatically on `npm install`. beacon.js reads os.hostname(), os.userInfo().username, and process.cwd(), base32-encodes them, and issues an HTTP GET to a hardcoded bare-IP callback URL http://45.76.249.245/beacon/\u003ctoken\u003e/techportal/4.0.10, carrying the values in X-Bug-Bounty-Host, X-Bug-Bounty-User, and X-Bug-Bounty-Path headers. If the HTTP beacon fails or times out, the same identifiers are packed as base32-encoded DNS subdomain labels and queried (resolve4/resolve6/resolveTxt) against three hardcoded `*.oob.asm5.net` collector domains, providing a DNS-tunneling channel that bypasses HTTP egress controls. Destination is not caller-configurable and there is no install-time opt-in. Self-labeling of the beacon as an authorized bug bounty or dual-use tool does not change the data flow: installer host identity leaves the installer's machine on `npm install` to hardcoded attacker-operated infrastructure.\n","modified":"2026-09-04T05:45:05.674251327Z","published":"2026-08-29T02:13:42Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-08-29T02:22:20.822240003Z","modified_time":"2026-08-29T02:13:42Z","sha256":"2d947d5b4ddaa0ea6a25488fb5b5a66b3afc5c8f56d5ac38fb2e95e4b23242f3","source":"amazon-inspector","versions":["4.0.10"],"id":"IN-MAL-2026-019138"},{"modified_time":"2026-09-04T05:20:51Z","sha256":"f3f611a34296fd636d0200171477f6b85e941d8a99464390df73c7680886c40c","source":"amazon-inspector","versions":["4.0.11"],"id":"IN-MAL-2026-019482","import_time":"2026-09-04T05:39:33.117536843Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/techportal/v/4.0.10"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/techportal/v/4.0.11"}],"affected":[{"package":{"name":"techportal","ecosystem":"npm","purl":"pkg:npm/techportal"},"versions":["4.0.10","4.0.11"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"sha256":"80aaaa62a836ace6c6bd876ea459446b17656bc9106501798d076dbd7ff91f87","tlsh":"75e0d8b6c0032d670956d4dea12a1083e959cc860a8e1831f34661d8094652f72f93cb","path":"beacon-config.json"},{"path":"beacon.js","sha256":"1f7e8753da396c8594f8e4ba93aabc476b0f0042b25b7e157daa3fbaffe38298","tlsh":"d1f1616591f220215b5361dce11b611ab679e2232c0eedc4bd5c97092f0bfecd0f6a9e"}],"package_integrity":[{"hashes":{"sha512_sri":"sha512-RmmCZmDzd6lxuiWo2/Hy4VPdNXaI1KByZlrZ7JAxPLU7rcjddggXfFw01GiCYPHpgXlm2k2u0x4CliYv3dtWOA==","sha1":"b81fd83b1ee513ec21c8ab1e76176093c014e03e"},"filename":"techportal-4.0.10.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/techportal/MAL-2026-15561.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}