{"id":"MAL-2026-17415","summary":"Malicious code in com.epi.e2e_test (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (5a0c1068af335818f2b9d905f2d39ebe594f84a6c63e470877692554bc95103b)\npackage.json declares a preinstall script that runs index.js on npm install. index.js collects host identifiers (os.homedir(), os.hostname(), os.userInfo().username, dns.getServers(), current working directory) along with the contents of the package.json and POSTs them over HTTPS to the hardcoded external host meta.brs.cx. This behavior fires automatically on install with no user interaction, and the collected data is characteristic of dependency-confusion / internal-name reconnaissance beacons used to identify targets for follow-on attacks.\n","modified":"2026-09-30T14:30:07.754439884Z","published":"2026-09-30T13:50:32Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-020822","import_time":"2026-09-30T14:21:25.191390953Z","modified_time":"2026-09-30T13:50:32Z","sha256":"5a0c1068af335818f2b9d905f2d39ebe594f84a6c63e470877692554bc95103b","source":"amazon-inspector","versions":["1.2.2"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/com.epi.e2e_test/v/1.2.2"}],"affected":[{"package":{"name":"com.epi.e2e_test","ecosystem":"npm","purl":"pkg:npm/com.epi.e2e_test"},"versions":["1.2.2"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"tlsh":"c711c0e4c1e123600dba55c47899d00816aad737780e6cd8f68d03d04fceabc70b2af1","path":"index.js","sha256":"6997cc0dbb734648576645638c3354b176fdd0f7ad89055626d752474a96237c"}],"package_integrity":[{"filename":"com.epi.e2e_test-1.2.2.tgz","hashes":{"sha512_sri":"sha512-HMkc/9uIkxiPGGLJGjhx0pREJCPWQ4U9zyvTX8tWENoiQN7Ui1nHVxDAKB7cYH13dv6uWHWxPFa4ALQwltl0nA==","sha1":"1915501cc527d33f0e9248146554cd01cc2d7311"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/com.epi.e2e_test/MAL-2026-17415.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}