{"id":"MAL-2026-16409","summary":"Malicious code in ubiquiti-agents-link-mcp (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (8827e987697ea6ef619055c53ae1654800a838c18419ffc8a09e872c6f16adc4)\nThe package's bin entry (index.js) runs `execSync('id')` and collects `os.userInfo().username` and `os.hostname()`, then HTTPS-POSTs the JSON payload to the hardcoded Burp Collaborator subdomain `uhffaanwxy0io5bfc0icu5lpug07o9cy.oastify.com` at a randomized path. The package occupies an npm name referenced by a vendor UI that instructs operators to invoke it via `npx`, so running the documented command causes host identity data to leave the operator's machine to a third-party OAST endpoint with no opt-in. The tarball metadata self-describes the release as a placeholder registered to demonstrate the dependency-confusion vector, but the shipped code performs a real installer-side data leak on execution, and the namespace remains available for future publishes by the same account with operator-level code execution on any host following the vendor's instruction.\n\n## Source: ossf-package-analysis (bb2bd11478a4b45a05adf8ac3c9b4ddeb169297b9c280916a25eccd4dd827922)\nThe OpenSSF Package Analysis project identified 'ubiquiti-agents-link-mcp' @ 0.0.1 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n","modified":"2026-09-23T02:30:05.495274356Z","published":"2026-09-22T19:50:54Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-09-22T20:17:17.852399391Z","modified_time":"2026-09-22T19:50:54Z","sha256":"bb2bd11478a4b45a05adf8ac3c9b4ddeb169297b9c280916a25eccd4dd827922","source":"ossf-package-analysis","versions":["0.0.1"]},{"versions":["0.0.2"],"import_time":"2026-09-22T20:40:21.481724192Z","modified_time":"2026-09-22T20:19:39Z","sha256":"b158c1e8beba133d0c5f07c85a0bfc80fe0e57d2bcbdf0e822464a43a70f1bbf","source":"ossf-package-analysis"},{"source":"amazon-inspector","versions":["0.0.1"],"id":"IN-MAL-2026-020314","import_time":"2026-09-22T22:16:11.644163054Z","modified_time":"2026-09-22T21:52:16Z","sha256":"26ca7cb3560e8fde1d27dacc2bbed1f2977ac793985ce681ffcb84badefc2d17"},{"versions":["0.2.0"],"id":"IN-MAL-2026-020308","import_time":"2026-09-22T22:16:11.092215219Z","modified_time":"2026-09-22T21:50:51Z","sha256":"7b6d6b384dff92a5d360b0655b27134e713b606471114fa03d1227901960a7ed","source":"amazon-inspector"},{"versions":["0.0.2"],"id":"IN-MAL-2026-020313","import_time":"2026-09-22T22:16:11.5772971Z","modified_time":"2026-09-22T21:52:08Z","sha256":"8827e987697ea6ef619055c53ae1654800a838c18419ffc8a09e872c6f16adc4","source":"amazon-inspector"},{"id":"IN-MAL-2026-020334","import_time":"2026-09-23T02:26:00.454098582Z","modified_time":"2026-09-23T01:58:37Z","sha256":"5fc7dc8a95dc5fd675809c56232bd62921143cda109be898194b2a03966894fb","source":"amazon-inspector","versions":["0.2.1"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/ubiquiti-agents-link-mcp/v/0.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/ubiquiti-agents-link-mcp/v/0.2.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/ubiquiti-agents-link-mcp/v/0.0.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/ubiquiti-agents-link-mcp/v/0.2.1"}],"affected":[{"package":{"name":"ubiquiti-agents-link-mcp","ecosystem":"npm","purl":"pkg:npm/ubiquiti-agents-link-mcp"},"versions":["0.0.1","0.0.2","0.2.0","0.2.1"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/ubiquiti-agents-link-mcp/MAL-2026-16409.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"path":"index.js","sha256":"b0dc582943ece637c6fef90b3dcb1c55aa19a9136ced62fd8d3ad9d25ea70b81","tlsh":"70f00ebca3f6007839f014c074507d5af05bc025b296a3c4f58d0f2081abcf451b9ac2"},{"tlsh":"11f04163147514630ac983101a71bfaf5b1680293243e351b33b736cb0260bc12373e7","path":"package.json","sha256":"7d73be709354b2a395d566edffcbbe54ba16ab294026bc432b9de08bb65ee0cb"}],"package_integrity":[{"hashes":{"sha512_sri":"sha512-gsGzv+fx89N+8v+KsbR00XmubjmDJuxHR4DkQQ/zyfXIjLpTKFwOFsSX+jbV3cledb1oqWn/TRMsQhZ5K8REMQ==","sha1":"0d410c17ae675f262c78ae5b8088dd8f897d1f6a"},"filename":"ubiquiti-agents-link-mcp-0.0.1.tgz"}]}}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}