{"id":"MAL-2026-17572","summary":"Malicious code in checkmate-remediation-assistant (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (c8f55d0ebeea19e228ec6edbb1782df87539c476478d3935559fda90a458b1b4)\nThe package's package.json declares a preinstall hook that runs index.js on npm install. index.js collects os.hostname(), os.userInfo(), the home directory, DNS server configuration, __dirname, the local package.json, and the contents of /etc/passwd and /etc/hosts, then transmits the collected data over HTTPS to a hardcoded Burp Collaborator (oastify.com) subdomain (9q0lp9mr6ek7nrnklhzkmbpuglmda4yt.oastify.com). The destination is an out-of-band interaction server not associated with any declared publisher or documented package purpose, and the exfiltration fires automatically on default install without user interaction.\n","modified":"2026-10-05T16:31:38.287546054Z","published":"2026-10-05T16:15:03Z","database_specific":{"malicious-packages-origins":[{"versions":["1.0.0"],"id":"IN-MAL-2026-021081","import_time":"2026-10-05T16:22:57.119740865Z","modified_time":"2026-10-05T16:15:03Z","sha256":"c8f55d0ebeea19e228ec6edbb1782df87539c476478d3935559fda90a458b1b4","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/checkmate-remediation-assistant/v/1.0.0"}],"affected":[{"package":{"name":"checkmate-remediation-assistant","ecosystem":"npm","purl":"pkg:npm/checkmate-remediation-assistant"},"versions":["1.0.0"],"database_specific":{"indicators":{"package_integrity":[{"hashes":{"sha512_sri":"sha512-Svgam2vzDqxOjZDANOlRGP+NDkxy6eyoq3NGdsJt2sUH+9YYxgnL8cxwM5DZG6T86bcT5JUS1tbJtHIYrCIrLw==","sha1":"1116b68d5c21ed65ff06b2edc7dfad7181636bf7"},"filename":"checkmate-remediation-assistant-1.0.0.tgz"}],"evidence_files":[{"path":"index.js","sha256":"c3b9a6b9837af57b17acac41d279a905d70365d3d9e57284c8c217b7508d78ca","tlsh":"5d412395a2c917330dd210c06a1c70843359fa777269a8d076cf42969f869f8b7326f3"}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/checkmate-remediation-assistant/MAL-2026-17572.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}