{"id":"MAL-2026-17542","summary":"Malicious code in @inpeek/odata (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (dad085b4b3e089d6a6d4e6812c66a8b45f10d40bc4ab39ea7bd0ce850d17ed4b)\n@inpeek/odata@99.99.100 is a dependency-confusion placeholder published to the public npm registry on the unregistered @inpeek scope with an inflated version (99.99.100) designed to outrank any internal release of the same name. The package.json declares a postinstall lifecycle hook that executes ping.js on `npm install`. ping.js performs an unconditional HTTPS GET to the hardcoded collector URL https://webhook.site/bec9d4b2-8f49-451e-84be-2681cb91ebf2, passing the installer's hostname (os.hostname()), platform (os.platform()), and Node.js version (process.version) as query parameters. index.js throws on require, so any accidental consumer breaks loudly after the postinstall beacon has already fired. The package self-labels as a bug-bounty research placeholder, but the install-time dataflow — automatic transmission of installer host identifiers to a third-party collector the installer did not opt into — is the dependency-confusion exploitation shape and reaches any installer whose tooling resolves @inpeek/* from the public registry.\n","modified":"2026-10-05T04:15:04.297717446Z","published":"2026-10-05T03:33:53Z","database_specific":{"malicious-packages-origins":[{"versions":["99.99.102"],"id":"IN-MAL-2026-021003","import_time":"2026-10-05T03:57:37.953396998Z","modified_time":"2026-10-05T03:33:53Z","sha256":"3f7aeb131f69bd5b75c9420a8825c9621e89453f275bc1e198eb62d93400b5ae","source":"amazon-inspector"},{"modified_time":"2026-10-05T03:34:13Z","sha256":"dad085b4b3e089d6a6d4e6812c66a8b45f10d40bc4ab39ea7bd0ce850d17ed4b","source":"amazon-inspector","versions":["99.99.100"],"id":"IN-MAL-2026-021005","import_time":"2026-10-05T03:57:38.085203734Z"},{"source":"amazon-inspector","versions":["99.99.99"],"id":"IN-MAL-2026-021029","import_time":"2026-10-05T03:57:40.048039974Z","modified_time":"2026-10-05T03:38:01Z","sha256":"5dd0a249ba1e978f084ca29dc0a5aca7b68da39a5510716ec5d7050bfd031647"},{"id":"IN-MAL-2026-021004","import_time":"2026-10-05T03:57:38.018271748Z","modified_time":"2026-10-05T03:34:03Z","sha256":"af0f490d6d86c37f78a097c8bac2644d66355151bf051fae9bd5e1f021d0d6db","source":"amazon-inspector","versions":["99.99.101"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@inpeek/odata/v/99.99.102"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@inpeek/odata/v/99.99.100"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@inpeek/odata/v/99.99.99"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@inpeek/odata/v/99.99.101"}],"affected":[{"package":{"name":"@inpeek/odata","ecosystem":"npm","purl":"pkg:npm/%40inpeek/odata"},"versions":["99.99.102","99.99.100","99.99.99","99.99.101"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"tlsh":"773187bf2651477017e802e87355745ad783f11ad8511dc0b9cf139847c15eb22216f3","path":"ping.js","sha256":"62e646e3c33a93cdbd7a45a82bc88a2fc79dff768f2a98c67aedc0bf517fc795"},{"tlsh":"b8f0ac6c99249d7222ec46e9083a5041f1256e8fd850bc4636db100d2b5e5eb52bc26e","path":"package.json","sha256":"f172accb07ca4abf3bff0583e1d04e59afb7ea7939a71c110d9a1b46b1061f5b"}],"package_integrity":[{"filename":"odata-99.99.102.tgz","hashes":{"sha1":"1e47bf1a874eb1c8a3f6502408058e1e827a117d","sha512_sri":"sha512-9kGKMd4YlGRDSyP08pjP03dl1QDo9pOsPzFTnXL7/TUlHqkTGRffAo/YYPm4/Zaxi/loU5IHPVJdF/zxgSOKsw=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@inpeek/odata/MAL-2026-17542.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}