{"id":"MAL-2026-4479","summary":"Malicious code in anthropic-shared-logger (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (e54ef50a83e2f379965286ed404d16ca3389a9ce5c8593718ef4e6f307cc6084)\nThis package impersonates Anthropic's internal namespace and self-describes as 'Full RCE PoC - Alex Birsan Style'. Its package.json declares a postinstall hook that, on every `npm install`, fetches the installer's public IP from api.ipify.org, runs `id || ver && whoami && hostname` via child_process.exec, and POSTs the hostname, current working directory, USERDOMAIN/COMPANY environment variables, IP address, and command output to a hardcoded Interactsh OOB endpoint at lszakfghwnvxspyfcmaabd1css99rnq3w.oast.fun over plain HTTP. The combination of namespace impersonation, automatic install-time shell execution, and host reconnaissance exfiltration to attacker-controlled out-of-band infrastructure is a canonical Birsan-style dependency confusion attack. Any build system that mis-resolves this name to the public registry leaks identity and host data to the attacker, enabling targeted follow-on compromise.\n","aliases":["GHSA-4vj8-cm74-gcx3"],"modified":"2026-09-01T11:31:00.219245926Z","published":"2026-05-21T00:09:42Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["8.0.5"],"id":"IN-MAL-2026-003657","import_time":"2026-05-26T05:51:03.407406712Z","modified_time":"2026-05-21T00:09:42Z","sha256":"754f7dc4855ecb1df012814bf5ec92a861958b7af0027d88d0a2cb918793cdce"},{"versions":["8.0.5"],"id":"IN-MAL-2026-003656","import_time":"2026-05-26T05:51:03.295053925Z","modified_time":"2026-05-21T00:09:42Z","sha256":"e54ef50a83e2f379965286ed404d16ca3389a9ce5c8593718ef4e6f307cc6084","source":"amazon-inspector"},{"sha256":"d7eb27d7306bba73ccc540f8b24d6b5b1a7ec3e5875240e9e1f1a36b85da1c1e","source":"reversing-labs","versions":["8.0.5"],"id":"RLMA-2026-04926","import_time":"2026-07-09T09:16:16.464372689Z","modified_time":"2026-07-07T12:38:23Z"},{"id":"RLUA-2026-06061","import_time":"2026-09-01T11:17:55.504431484Z","modified_time":"2026-08-24T16:38:56Z","sha256":"0b586996c40c96903c002f3280f3257e4814f86846b5fba1ff7683d93c04bbb0","source":"reversing-labs"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/anthropic-shared-logger/v/8.0.5"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-4vj8-cm74-gcx3"}],"affected":[{"package":{"name":"anthropic-shared-logger","ecosystem":"npm","purl":"pkg:npm/anthropic-shared-logger"},"versions":["8.0.5"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"domains":["api.ipify.org"],"evidence_files":[{"path":"package.json","sha256":"c5ee2909d9b5fd81e5446da44cb585c48d5d0847c88622a2e13e9a15894df7ea","tlsh":"8b1179f0dac4d5b9a3d107f97d43d501fd23e75911105cb0e96c16414b45170259be9c"}],"package_integrity":[{"filename":"anthropic-shared-logger-8.0.5.tgz","hashes":{"sha1":"42ac708d3461fe7c7e6b03558034a794f4cc49d3","sha512_sri":"sha512-qd0sKM/4kBkd83Ne7r8kz0CwuiO+awnOeF1bWE+MHBnxJYNsny6ImoFvvaw7YtQF3nVAL05PrHKisfKRXtTRgA=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/anthropic-shared-logger/MAL-2026-4479.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}