{"id":"MAL-2026-15589","summary":"Malicious code in autobahn-electron-probe (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (b9a749e23bbf7c5ca871c797923855dc2c7fe1006c5843ed8a13292d7fbd4256)\npackage.json declares preinstall and postinstall lifecycle scripts that run curl against http://da9ohqqvbsgu1166tuu0rrroxsztr18dt.cyowl.com/autobahn-electron-probe/, sending the installer's username (whoami), hostname, current working directory, and a timestamp as query parameters over plain HTTP. The long unique subdomain under cyowl.com is a DNS-callback / OAST-style exfiltration pattern. The scripts fire automatically on npm install without any user action, and the package ships no functional module code — the lifecycle beacon is the entire payload. The package name resembles the Autobahn WebSocket project and Electron, but the shipped contents perform only host reconnaissance and beaconing.\n\n## Source: ossf-package-analysis (d3c07ff64c9729469df8453fb5fd6fa15e1099e81916496d741fe10297e44fc7)\nThe OpenSSF Package Analysis project identified 'autobahn-electron-probe' @ 99.99.1 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package executes one or more commands associated with malicious behavior.\n","modified":"2026-08-31T18:31:22.348675869Z","published":"2026-08-30T01:25:47Z","database_specific":{"malicious-packages-origins":[{"versions":["99.99.1"],"import_time":"2026-08-30T23:14:56.177874547Z","modified_time":"2026-08-30T01:25:47Z","sha256":"d3c07ff64c9729469df8453fb5fd6fa15e1099e81916496d741fe10297e44fc7","source":"ossf-package-analysis"},{"sha256":"12dc0a5dd6ee92d1530068fa541791305711fad5f9b206ebee22b22f164692a5","source":"amazon-inspector","versions":["99.99.1"],"id":"IN-MAL-2026-019175","import_time":"2026-08-31T17:16:14.386846818Z","modified_time":"2026-08-31T16:49:18Z"},{"source":"amazon-inspector","versions":["99.99.2"],"id":"IN-MAL-2026-019316","import_time":"2026-08-31T18:22:30.099751588Z","modified_time":"2026-08-31T18:04:07Z","sha256":"44facef09636d88a5a2b6c5ebd5313bcc3282654125320ff922fac9bd1051c89"},{"source":"amazon-inspector","versions":["99.99.3"],"id":"IN-MAL-2026-019313","import_time":"2026-08-31T18:22:29.89482128Z","modified_time":"2026-08-31T18:03:40Z","sha256":"b9a749e23bbf7c5ca871c797923855dc2c7fe1006c5843ed8a13292d7fbd4256"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/autobahn-electron-probe/v/99.99.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/autobahn-electron-probe/v/99.99.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/autobahn-electron-probe/v/99.99.3"}],"affected":[{"package":{"name":"autobahn-electron-probe","ecosystem":"npm","purl":"pkg:npm/autobahn-electron-probe"},"versions":["99.99.1","99.99.2","99.99.3"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"path":"package.json","sha256":"96594d73700eb0e763fb127749be327a2b583dcacaa7dc07db6785bc4ba7049f","tlsh":"2ef04664f42268b33dc58f695cc0c60b39301d4b0318a602464bec082bed26757ba21b"}],"package_integrity":[{"hashes":{"sha512_sri":"sha512-mSowWvbhkU0RiUYGesXFIXyoFrVd+EzVcSVrQpfaajYFltJzY/hGHBfWzleUCrm98RAlEZj3KQ+T1MUs+dIs9A==","sha1":"65123691e8570f9a9084e48ce2015306ea4b9ccb"},"filename":"autobahn-electron-probe-99.99.1.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/autobahn-electron-probe/MAL-2026-15589.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}