{"id":"MAL-2026-4525","summary":"Malicious code in claude-internal-utils (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (24a94a290c15f2b6cdaf351590455cd597bb2881f7bbcf1609fbfbd8031e491f)\nPackage name impersonates an internal Anthropic 'claude-*' namespace and the description field self-identifies as 'Alex Birsan Style' dependency-confusion bait. The package ships no library code; its only effect is a postinstall lifecycle hook that runs an inline node one-liner which fetches the installer's public IP from api.ipify.org, executes `id || ver && whoami && hostname` via child_process.exec, and POSTs hostname, cwd, USERDOMAIN/COMPANY env vars, public IP, package name, and the command output as JSON to a hardcoded attacker subdomain at lszakfghwnvxspyfcmaabd1css99rnq3w.oast.fun (an out-of-band interaction service commonly used for exfiltration). Fires automatically on `npm install`, before any consumer code runs.\n","aliases":["GHSA-jxg3-fwfv-fjwf"],"modified":"2026-09-01T11:31:31.736382837Z","published":"2026-05-20T23:55:57Z","database_specific":{"malicious-packages-origins":[{"sha256":"0907de4f4ae6bbfa72bdca010597aeac418f4c6c6e0af3c5516c3a5041171b55","source":"amazon-inspector","versions":["9.0.5"],"id":"IN-MAL-2026-003653","import_time":"2026-05-26T05:51:03.000265919Z","modified_time":"2026-05-20T23:55:58Z"},{"id":"IN-MAL-2026-003652","import_time":"2026-05-26T05:51:02.904736044Z","modified_time":"2026-05-20T23:55:57Z","sha256":"24a94a290c15f2b6cdaf351590455cd597bb2881f7bbcf1609fbfbd8031e491f","source":"amazon-inspector","versions":["9.0.5"]},{"import_time":"2026-07-09T09:16:25.347967007Z","modified_time":"2026-07-07T12:44:23Z","sha256":"fe2d6104d5c25a301ebf66c3def5d32ec6090eda230b42103b40e4d99650c134","source":"reversing-labs","versions":["9.0.5"],"id":"RLMA-2026-05024"},{"modified_time":"2026-08-24T16:44:30Z","sha256":"30fcdc67f2b934ea3e072c939ec890f9563ef739698e33ca5df0f7459e0d6112","source":"reversing-labs","id":"RLUA-2026-06154","import_time":"2026-09-01T11:18:00.464035617Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/claude-internal-utils/v/9.0.5"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-jxg3-fwfv-fjwf"}],"affected":[{"package":{"name":"claude-internal-utils","ecosystem":"npm","purl":"pkg:npm/claude-internal-utils"},"versions":["9.0.5"],"database_specific":{"indicators":{"evidence_files":[{"tlsh":"231135f19990eb75e3d157f87a17d405ed63e70b61108cb0a86c17814b841b0559bf9c","path":"package.json","sha256":"166f1e78f5f9fe79fe80e3a19f920599f6c24a7b295ad06de5771a9ee951e2df"}],"package_integrity":[{"filename":"claude-internal-utils-9.0.5.tgz","hashes":{"sha1":"3df62d23421424de8d48f5ff596f5a40fd18698e","sha512_sri":"sha512-fQLCcZl8UM/xyFAy9LemVh2Zq/z98d7scs4W3HWHh7VEryxFS8MhxlejJESkMRebLB1AsQhAh6Kn8B3WZUcueg=="}}],"domains":["lszakfghwnvxspyfcmaabd1css99rnq3w.oast.fun","api.ipify.org"]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/claude-internal-utils/MAL-2026-4525.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}]}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}