{"id":"MAL-2026-3810","summary":"Malicious code in @pluxee-connect/account-db-api-client (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (49a36af66b1c55fbf7a78529c1fe2d15b819cef018300a03cdc8e0a1b59f36c9)\nVersion 99.0.0 of this package targets an internal-looking npm scope and ships a postinstall.js that, on every `npm install`, reads os.hostname(), os.userInfo().username, process.version, and the package name and transmits them to the third-party OAST domain `d84t2rmqt3fpphmbii3gf9sdi63c3gkp7.oast.online` over both HTTP GET (port 80) and DNS lookup. The package's main entry (index.js) is a placeholder stub containing only a ConsentsStatus enum with a comment self-describing it as a `PoC stub` mirroring the real package's API. The combination of an inflated 99.0.0 version, a hollow API surface, and an unconditional install-time beacon to an interactsh out-of-band exfiltration host on a scope that resembles an internal Pluxee namespace is a textbook dependency-confusion attack: any build system misresolving the internal name to this public package leaks host identity to the attacker's OAST listener.\n\n## Source: ossf-package-analysis (b7d101dbff5c071f3bab34e97f3d340e0b52caa00e38ef82e630864d44a7dce3)\nThe OpenSSF Package Analysis project identified '@pluxee-connect/account-db-api-client' @ 99.0.0 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n","modified":"2026-05-26T06:01:57.711634791Z","published":"2026-05-17T14:51:10Z","database_specific":{"malicious-packages-origins":[{"versions":["99.0.0"],"source":"ossf-package-analysis","sha256":"b7d101dbff5c071f3bab34e97f3d340e0b52caa00e38ef82e630864d44a7dce3","import_time":"2026-05-17T15:26:55.415931472Z","modified_time":"2026-05-17T14:51:10Z"},{"source":"amazon-inspector","sha256":"5bf0b2245dd636268ec39543616b01a112a5fefdcd1e0bb3871253c9d6c66f16","import_time":"2026-05-19T17:50:18.539159308Z","modified_time":"2026-05-19T16:47:48Z","versions":["99.0.0"]},{"source":"amazon-inspector","sha256":"2f7a7dc221fc21232e339e65cab2b61e23dbfe8d558f180655baef639074ca64","import_time":"2026-05-26T05:50:40.334678781Z","id":"IN-MAL-2026-003453","modified_time":"2026-05-20T03:59:16Z","versions":["99.0.0"]},{"modified_time":"2026-05-20T03:59:16Z","versions":["99.0.0"],"source":"amazon-inspector","sha256":"49a36af66b1c55fbf7a78529c1fe2d15b819cef018300a03cdc8e0a1b59f36c9","import_time":"2026-05-26T05:50:40.227691547Z","id":"IN-MAL-2026-003452"},{"sha256":"665582dfdf3ec83c50aced3777adb2b4a51ddc054cd07b9af0dd4d8e28896cec","import_time":"2026-05-26T05:50:57.473949943Z","id":"IN-MAL-2026-003607","modified_time":"2026-05-20T19:44:13Z","versions":["99.0.1"],"source":"amazon-inspector"},{"source":"amazon-inspector","sha256":"9104569f9f07e32685849b839c9620452f9ae03afc4706147f999a5bd6ae43fe","import_time":"2026-05-26T05:50:57.331061468Z","id":"IN-MAL-2026-003606","modified_time":"2026-05-20T19:44:12Z","versions":["99.0.1"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@pluxee-connect/account-db-api-client/v/99.0.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@pluxee-connect/account-db-api-client/v/99.0.1"}],"affected":[{"package":{"name":"@pluxee-connect/account-db-api-client","ecosystem":"npm","purl":"pkg:npm/%40pluxee-connect%2Faccount-db-api-client"},"versions":["99.0.0","99.0.1"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@pluxee-connect/account-db-api-client/MAL-2026-3810.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"domains":["scan-5d9d8f7cef77.scan.d84t2rmqt3fpphmbii3gf9sdi63c3gkp7.oast.online","d84t2rmqt3fpphmbii3gf9sdi63c3gkp7.oast.online"],"evidence_files":[{"sha256":"1780ded65508f58b622451654afff15cd13d32bb40e3136c40d3e2338d407b3f","tlsh":"29016dd485e9d63019fb15d8b79b481e90dbe202795acc80f5be42d00f6753986619b8","path":"postinstall.js"},{"tlsh":"a5d0959392d61314694308d0f10fcd43bf41147213050b88060cc14cd4f8acd3cb35d4","path":"index.js","sha256":"730c728f317c8d0daed1c41bfc9847995f9898183110aa9ac19feb0de5fa06c8"}],"package_integrity":[{"filename":"account-db-api-client-99.0.0.tgz","hashes":{"sha1":"8fbb62a9a87cacf1635ed84b16675cd20f3a4790","sha512_sri":"sha512-uyuSxszyI+Elrw+2WDI9hxQn3D24zN1ADL8gMX2IV7RKpC0j8CfiWGM3NN2PsmjFhpjXk3bkUbg1IvczMhV63g=="}}]}}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}