{"id":"MAL-2026-16435","summary":"Malicious code in catqrcodeconverter (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (3333f7b95e551ebf6ed266fb1de661b7419520ed3a922b05910ede132c7d6757)\nPackage catqrcodeconverter@99.2.1 wires both preinstall and postinstall lifecycle hooks in package.json to execute scripts/run.js. On npm install, run.js reads the installer's OS username via os.userInfo() and hostname via os.hostname() and POSTs them as JSON (with the package name) to a hardcoded collector at https://webhook.site/8beeee0f-4dd4-4b25-8588-5a5f83fe6ed2, and issues a DNS canary lookup to 8beeee0f-4dd4-4b25-8588-5a5f83fe6ed2.dnshook.site. The implausibly high version number (99.2.1) is consistent with a dependency-confusion lure intended to win resolution against an internal package name. Installer host identifiers are transmitted to an attacker-controlled endpoint without any user interaction beyond the install command.\n","modified":"2026-09-23T02:00:07.785002273Z","published":"2026-09-23T01:40:42Z","database_specific":{"malicious-packages-origins":[{"sha256":"3333f7b95e551ebf6ed266fb1de661b7419520ed3a922b05910ede132c7d6757","source":"amazon-inspector","versions":["99.2.1"],"id":"IN-MAL-2026-020326","import_time":"2026-09-23T01:50:19.111490213Z","modified_time":"2026-09-23T01:40:42Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/catqrcodeconverter/v/99.2.1"}],"affected":[{"package":{"name":"catqrcodeconverter","ecosystem":"npm","purl":"pkg:npm/catqrcodeconverter"},"versions":["99.2.1"],"database_specific":{"indicators":{"evidence_files":[{"sha256":"e663687cf6e937c9ab29f0da15647930df294f318ba74ec281f25359bc604783","tlsh":"812111e748f841242eb341c0674fec5aa227e6067443ead0ba9d03221fc5afc46739f8","path":"scripts/run.js"}],"package_integrity":[{"filename":"catqrcodeconverter-99.2.1.tgz","hashes":{"sha1":"8342932e947043000943693abd7dacfa2b9463ff","sha512_sri":"sha512-yx8U3XYgFcoGhf6VweYNUZh5WN+R28ZIebeIG896JkaBIYHXk9p65ZYkOC9xudH2YeCfJ3tovEcOk5wolU5VTg=="}}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/catqrcodeconverter/MAL-2026-16435.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}