{"id":"MAL-2026-16063","summary":"Malicious code in alloy-graphql (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (80ee3815d12ec95aedb4bbe0d3de5c516e99163ca1eba52c2a3de7038b9a2ac0)\npackage.json declares a preinstall hook that runs index.js on npm install. The script collects hostname, username, home directory, DNS servers, current working directory, and package.json contents, and reads /etc/passwd and /etc/hosts from the installer's host. The collected data is HTTPS-POSTed to a hardcoded Burp Collaborator subdomain at ipbtwv9063nc5hvhodh0s4u9x03rrhf6.oastify.com. The package has no advertised functionality beyond this exfiltration payload.\n","modified":"2026-09-09T02:00:04.588072421Z","published":"2026-09-09T01:40:48Z","database_specific":{"malicious-packages-origins":[{"versions":["1.0.1"],"id":"IN-MAL-2026-019744","import_time":"2026-09-09T01:51:48.534172403Z","modified_time":"2026-09-09T01:40:48Z","sha256":"80ee3815d12ec95aedb4bbe0d3de5c516e99163ca1eba52c2a3de7038b9a2ac0","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/alloy-graphql/v/1.0.1"}],"affected":[{"package":{"name":"alloy-graphql","ecosystem":"npm","purl":"pkg:npm/alloy-graphql"},"versions":["1.0.1"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/alloy-graphql/MAL-2026-16063.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"package_integrity":[{"filename":"alloy-graphql-1.0.1.tgz","hashes":{"sha1":"f1c5d0f5e0e0a0d682dd3489c81699dc2aac96b2","sha512_sri":"sha512-C5PZa+V4b+XLYATcEpBEPFDkvJHN6K7sF8hQ0o1XNIojlJm1ap5n8ZDjUGtWtks5t3urea9ukIEIQge70fG+6A=="}}],"evidence_files":[{"tlsh":"fe41259562d917330dd210c06a0c74842359fa777159989076cf42969f869f8b7326f3","path":"index.js","sha256":"1ef69efc0a4501621068e82c56f47cc97b6ff49f577365a00f88154955eaa0ae"}]}}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}