{"id":"MAL-2026-16140","summary":"Malicious code in tracker-cloudflare (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (55b5bacf5779f1a1fa161ee38acbf61fda0dc18b3d0fe35213e2b0dc230c06e4)\nThe package's preinstall hook runs `node index.js`, which collects host identifiers (os.hostname, os.userInfo, homedir, DNS servers, cwd) along with the contents of /etc/passwd and /etc/hosts, and POSTs the payload over HTTPS to the Burp Collaborator subdomain c6j5cmm8sia88v4zyhykqvhvcmid65uu.oastify.com. The package has empty description/author metadata and no legitimate functionality beyond this beacon. The exfiltration fires automatically on `npm install` before any consumer code runs.\n","modified":"2026-09-11T23:30:06.175297037Z","published":"2026-09-11T22:39:35Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-09-11T22:39:35Z","sha256":"55b5bacf5779f1a1fa161ee38acbf61fda0dc18b3d0fe35213e2b0dc230c06e4","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-020010","import_time":"2026-09-11T23:15:29.803859676Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/tracker-cloudflare/v/1.0.0"}],"affected":[{"package":{"name":"tracker-cloudflare","ecosystem":"npm","purl":"pkg:npm/tracker-cloudflare"},"versions":["1.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/tracker-cloudflare/MAL-2026-16140.json","indicators":{"evidence_files":[{"sha256":"90cc578c4cf43a176e88bfb2fa8d0b9edd20a748a19441463520b1598390f765","tlsh":"d741259592d917330dd210c06a0c70802359f9777259e89076cf4396af869f8b7326f3","path":"index.js"},{"path":"package.json","sha256":"6b7b6b3c821232b5db628ed141b7e176158e2abba3ad27bbbe6660d2324a8b1c","tlsh":"eed0a7344d62563325c146a60c3b999773a18f2f04043c08a3cb582d91ce7b798ff30c"}],"package_integrity":[{"filename":"tracker-cloudflare-1.0.0.tgz","hashes":{"sha1":"da38ef300dece7d8619e5be8206a0dc46b7871b7","sha512_sri":"sha512-2XLu4DIT82TVH3YspTqpeUqsfB4yEO7GTlMU8EYkseDzubr15tYgenLDNYG3ry32C9Shz2k8EQh2FMbrFC2q3w=="}}]},"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}]}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}