{"id":"MAL-2026-16314","summary":"Malicious code in test1hh235 (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (c9c95dc5aea7805ca50e114bae45747a46edb7331311044b0d3730e303d4351a)\nPackage declares both preinstall and postinstall lifecycle hooks that execute index.js on `npm install`. index.js issues an HTTP GET to the hardcoded bare IP 128.199.122.145 over plain HTTP, embedding the package name in the query string (`http://128.199.122.145/?test1hh235`). Manifest shape is consistent with a dependency-confusion reconnaissance probe: version 99.99.99 (implausibly high to win resolution against an internal package), empty description, and a typo-prone name. The beacon fires automatically during install and signals successful resolution/installation to an attacker-controlled host, confirming the target environment for follow-on attack.\n","modified":"2026-09-21T03:30:17.628630018Z","published":"2026-09-21T03:23:01Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["99.99.99"],"id":"IN-MAL-2026-020208","import_time":"2026-09-21T03:24:21.631054197Z","modified_time":"2026-09-21T03:23:01Z","sha256":"c9c95dc5aea7805ca50e114bae45747a46edb7331311044b0d3730e303d4351a"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/test1hh235/v/99.99.99"}],"affected":[{"package":{"name":"test1hh235","ecosystem":"npm","purl":"pkg:npm/test1hh235"},"versions":["99.99.99"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"package_integrity":[{"filename":"test1hh235-99.99.99.tgz","hashes":{"sha512_sri":"sha512-3jS2BoDc41uOGgEagxN4fIzWW/YhmbdgMpawrmMmmnnL/9/4LmfJB8Bg685iAKQiROZ603OGaFMrH5eiLeRW9w==","sha1":"612eafede0c18009855b78e5a57881c81403a2fb"}}],"evidence_files":[{"path":"index.js","sha256":"129935ea1b3fdc6a7e4520d292016a7392be70150e25a08f27734bec451f0544","tlsh":"89c08cc26382f38486f9088369291616230df170b9fc04b6e34c63ae489396d11a3ac1"},{"path":"package.json","sha256":"5eae61ba4b622d5d28e9571d0d08a0fe8ff85512b89778c353627c8557faa761","tlsh":"bde09261cc509a7310fc12e568791b07f1625f2b82685c0b34f3b48d66a2126449ef29"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/test1hh235/MAL-2026-16314.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}