{"id":"MAL-2026-17214","summary":"Malicious code in git-en-boite-logging (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (f6ebee9f4428d7f14f6f941438064715c8bece34c5fe6bfedf32bbd8cba226c0)\npackage.json declares a preinstall lifecycle hook that runs `wget` to a hardcoded webhook.site collector URL (https://webhook.site/3fcfa5af-1b4e-4556-9d48-26190d02795f/), passing `$(whoami)`, `$(hostname)`, and `$(pwd)` as query parameters. On `npm install`, npm invokes the preinstall script automatically, so the installer's OS username, host name, and current working directory are transmitted to an anonymous third-party webhook collector without any user action. This is the canonical dependency-confusion / reconnaissance beacon shape: an otherwise-empty package whose only on-install effect is to phone home installer identity to an attacker-chosen endpoint, typically used to confirm ingress into a target's internal build environment before staging a follow-on payload.\n","modified":"2026-09-28T14:30:08.219570801Z","published":"2026-09-28T14:18:12Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-09-28T14:21:43.654845338Z","modified_time":"2026-09-28T14:18:12Z","sha256":"f6ebee9f4428d7f14f6f941438064715c8bece34c5fe6bfedf32bbd8cba226c0","source":"amazon-inspector","versions":["0.0.0"],"id":"IN-MAL-2026-020579"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/git-en-boite-logging/v/0.0.0"}],"affected":[{"package":{"name":"git-en-boite-logging","ecosystem":"npm","purl":"pkg:npm/git-en-boite-logging"},"versions":["0.0.0"],"database_specific":{"indicators":{"evidence_files":[{"path":"package.json","sha256":"eeeb7167a98450e8be74ff678e8b1e72ba1c68ed75fd157f1352d5e90dfdfe30","tlsh":"5f01d334f620b92307c597a15525461bba32fba7da1a6c0deba71259531d8ea0078a18"}],"package_integrity":[{"hashes":{"sha1":"9b6320e561bb6b58d363bface8b6c6f90fea6c28","sha512_sri":"sha512-NpfFTMEfKE1HF+2F7ZE66DoiQj017DTFOa4a1glV0xG0lthw4cwFH6PnFVjERMxGYlnyeUHVEk8q+VxobgInkQ=="},"filename":"git-en-boite-logging-0.0.0.tgz"}]},"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/git-en-boite-logging/MAL-2026-17214.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}