{"id":"MAL-2026-17579","summary":"Malicious code in with-cte (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (8eceeb0a05cd8d1a289f1a1006df8acd825d73f341ec1a50e095dc2850b866c8)\nThe package declares a preinstall lifecycle hook (`preinstall: node index.js`) that runs automatically on `npm install`. index.js collects installer host identifiers (os.hostname, os.userInfo, homedir, DNS servers) and reads the contents of /etc/passwd and /etc/hosts, then POSTs the collected data over HTTPS to the Burp Collaborator subdomain 187d714jo62z5j5c39hc437myd44sxgm.oastify.com. The package otherwise contains no library code, has empty author/description metadata, and provides no functionality — the shipped surface is solely the install-time beacon, consistent with a dependency-confusion or internal-name squat probe.\n","modified":"2026-10-05T16:31:37.055131147Z","published":"2026-10-05T16:14:55Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-10-05T16:14:55Z","sha256":"8eceeb0a05cd8d1a289f1a1006df8acd825d73f341ec1a50e095dc2850b866c8","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-021080","import_time":"2026-10-05T16:22:57.062637671Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/with-cte/v/1.0.0"}],"affected":[{"package":{"name":"with-cte","ecosystem":"npm","purl":"pkg:npm/with-cte"},"versions":["1.0.0"],"database_specific":{"indicators":{"evidence_files":[{"path":"index.js","sha256":"9f166ed0f6ddc8c6af3cdecd03dc086fa3921102a3c569d92326718e028f7103","tlsh":"33411399a2d917330de114c06a0c70852359fa777159a8d076cf4396af869f8b7226f3"},{"path":"package.json","sha256":"57f305d98ee36961808b9408ddb98d5d0b15ea1b77e09564860d2b843f8060f9","tlsh":"4fd0a7384d21553325c516a20c2b944772618f2f04043c0863cb182c91ce77798ff35c"}],"package_integrity":[{"filename":"with-cte-1.0.0.tgz","hashes":{"sha1":"c182f210794123466d1568c3d909160e0f34e52e","sha512_sri":"sha512-Hbkil57Pefuv1lLN9G2JJyU7M1x65dbCqf/uLxDGND4Y+3Ky4m3nZKq61ZInD7Dd+ZMG8cgI2TsOgbtMhFnDpQ=="}}]},"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/with-cte/MAL-2026-17579.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}