{"id":"MAL-2026-17437","summary":"Malicious code in @bluewin/utils (npm)","details":"@bluewin/utils is a dependency-confusion package: it describes itself as a \"PoC package for dependency confusion testing\" and claims the `@bluewin` scope, so a build that resolves that scope from the public registry runs its code instead of the intended private package. Its postinstall script runs `node postinstall.js` on npm install, which sends an HTTPS request to `https://5w2cezr3af2i0rvm72x74empvg18pzdo.oastify.com/bluewin/utils`, a Burp Collaborator endpoint, disclosing the installing host's IP address and that it installed the package. It collects no further data, but unreviewed code from an outside publisher has run with the installing user's privileges. The npm account securityresearch1 published it on 2026-10-01.","modified":"2026-10-02T05:01:12.420231240Z","published":"2026-10-01T02:40:08Z","database_specific":{"iocs":{"urls":["https://5w2cezr3af2i0rvm72x74empvg18pzdo.oastify.com/bluewin/utils"],"domains":["5w2cezr3af2i0rvm72x74empvg18pzdo.oastify.com"],"files":[{"note":"postinstall script: node postinstall.js","paths":["package.json"],"source":"PACKAGE_ARCHIVE","digests":{"sha256":"628e04ce4e3165269e4505b10af93a2df7f689fad6bcbf49409d7be7e18bf300"}},{"source":"PACKAGE_ARCHIVE","digests":{"sha256":"68324659e177d6de76125da39ab3ca96e27a9d3890692a12a652c18471163770"},"note":"Executed by the postinstall script of @bluewin/utils@1.0.0.","paths":["postinstall.js"]}]}},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@bluewin/utils"}],"affected":[{"package":{"name":"@bluewin/utils","ecosystem":"npm","purl":"pkg:npm/%40bluewin/utils"},"versions":["1.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@bluewin/utils/MAL-2026-17437.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}]}}],"schema_version":"1.9.0","credits":[{"name":"InvisiRisk, Inc.","contact":["https://www.invisirisk.com","mailto:research@invisirisk.com"],"type":"FINDER"}]}