{"id":"MAL-2026-16361","summary":"Malicious code in @uh-platform/nadaver2 (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (c35cffdc174427ac57ea3c5e8ac02ec41159f8f25ffe1ef152e0437e5e533458)\nThe package's package.json declares a preinstall lifecycle hook that runs `node index.js`. index.js invokes child_process.exec on a curl command whose URL embeds `$(hostname)` and `$(whoami)` as DNS subdomains of `nadaver.pa33pg1od9cr4ffnrzec8864jvpmdd12.oastify.com`, a Burp Collaborator (OAST) endpoint. On `npm install`, the installer's hostname and OS username are transmitted to that attacker-controlled collaborator host via DNS and HTTP. The `@uh-platform` scope and the name shape are consistent with a dependency-confusion probe. There is no legitimate SDK, build, or install functionality in the package.\n","modified":"2026-09-21T19:30:05.810965764Z","published":"2026-09-21T18:56:00Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-09-21T19:14:59.511337063Z","modified_time":"2026-09-21T18:56:00Z","sha256":"c35cffdc174427ac57ea3c5e8ac02ec41159f8f25ffe1ef152e0437e5e533458","source":"amazon-inspector","versions":["102.0.0"],"id":"IN-MAL-2026-020267"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@uh-platform/nadaver2/v/102.0.0"}],"affected":[{"package":{"name":"@uh-platform/nadaver2","ecosystem":"npm","purl":"pkg:npm/%40uh-platform/nadaver2"},"versions":["102.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"tlsh":"3ee02d0849fc943632629854fc2e881e76079902123ff2837ecfa70027c0a48c01c2da","path":"index.js","sha256":"0f435996c65085fe581bc4a48ba26ebb85b1955da6a516c34a0323dc06b07774"}],"package_integrity":[{"filename":"nadaver2-102.0.0.tgz","hashes":{"sha512_sri":"sha512-6TjWXDSCST3hNfEGuEP8rBMPuRD8fXQmqKFnb48osTdga8zuzNfAQmZKyGZWG3celf4cKHZmWOwoWzkjNPnb8Q==","sha1":"78913b4374b0282811b90f1eefa5d587a0c369ff"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@uh-platform/nadaver2/MAL-2026-16361.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}