{"id":"MAL-2026-4587","summary":"Malicious code in intl-ads (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (c7e29be11c53c137c2a24258ae423cf422fefcaad06183d67aa5c895a8fe4801)\nOn `npm install`, the package's `scripts.preinstall` runs poc.js which collects hostname, username, full network configuration (ipconfig/ip a/resolv.conf), `id`/`whoami /all`, git remote, parent package.json, and CI configuration files (.gitlab-ci.yml,.github/workflows, Jenkinsfile, azure-pipelines.yml). It then iterates `process.env` and harvests any variable whose name contains AWS, AZURE, GITHUB, GITLAB, JENKINS, NPM, TOKEN, CI, BUILD, etc. — capturing values, not just names — and POSTs the JSON payload to `d8a5d9pon5bugoc35cngp9hcregcqyezu.oast.me` over HTTPS, with a DNS callback as a secondary channel. The package self-describes as authorized bug-bounty research targeting Walmart's private namespace via dependency confusion, but the public npm registry has no scope restriction: any developer or CI system that resolves this name will execute the recon and leak credentials. The OAST destination is an Interactsh collector, not a Walmart-owned endpoint, so harvested data leaves any authorized scope. Concrete installer harm: AWS/Azure/GitHub/GitLab/npm tokens present in CI environment are exfiltrated; host fingerprinting enables follow-on attacks.\n","modified":"2026-05-26T06:02:37.553687409Z","published":"2026-05-25T13:57:57Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-05-25T14:04:48Z","sha256":"0e3ef1ac43fa8e2f7a5e780c59071356afe6c000141639d1964338bf6234e8b0","source":"amazon-inspector","versions":["99.0.1"],"id":"IN-MAL-2026-004666","import_time":"2026-05-26T05:53:03.032119287Z"},{"source":"amazon-inspector","versions":["99.0.0"],"id":"IN-MAL-2026-004664","import_time":"2026-05-26T05:53:02.820436739Z","modified_time":"2026-05-25T13:57:58Z","sha256":"74af72febe42133dcf81ad5910fc4ca98293df63ae8f8de60165db1c6fa49832"},{"source":"amazon-inspector","versions":["99.0.1"],"id":"IN-MAL-2026-004667","import_time":"2026-05-26T05:53:03.124260823Z","modified_time":"2026-05-25T14:04:48Z","sha256":"943b5422a0d6d362eeecd14087b149836b80a997a347731eeb93a64c1926e7e4"},{"versions":["99.0.2"],"id":"IN-MAL-2026-004674","import_time":"2026-05-26T05:53:03.855274117Z","modified_time":"2026-05-25T14:09:54Z","sha256":"c7e29be11c53c137c2a24258ae423cf422fefcaad06183d67aa5c895a8fe4801","source":"amazon-inspector"},{"id":"IN-MAL-2026-004663","import_time":"2026-05-26T05:53:02.719339662Z","modified_time":"2026-05-25T13:57:57Z","sha256":"e97850316cad977b2e7bc006034b3c7d7ab1aca8ff13f98a49420a2a7a400ee4","source":"amazon-inspector","versions":["99.0.0"]},{"sha256":"2dad6bce5816c5d7f31035825cfb9f741f6863bca59221dac4308e110256e7d0","source":"amazon-inspector","versions":["99.0.2"],"id":"IN-MAL-2026-004675","import_time":"2026-05-26T05:53:03.986537211Z","modified_time":"2026-05-25T14:09:55Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/intl-ads/v/99.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/intl-ads/v/99.0.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/intl-ads/v/99.0.0"}],"affected":[{"package":{"name":"intl-ads","ecosystem":"npm","purl":"pkg:npm/intl-ads"},"versions":["99.0.1","99.0.0","99.0.2"],"database_specific":{"indicators":{"domains":["d8a56vpon5budaeafq00tsyj88aqd5m7p.oast.pro"],"evidence_files":[{"sha256":"8b87b23b345fd282383ca2d4d11a166c5b242639464c71b4bb4d915c1d43a899","tlsh":"ba3165d615f9647036b6f6c0b0d6ad515367e333b54af8e42588094162cf9f141f52e4","path":"poc.js"},{"sha256":"55335b51a17b25f8ed7774270dafe46be307c30485360022c576e7a65b162a8f","tlsh":"fce07d781510102316e8c3fa05b65847a128cd0b51086c190b53344c82eeba301bfb5d","path":"package.json"}],"package_integrity":[{"filename":"intl-ads-99.0.1.tgz","hashes":{"sha512_sri":"sha512-pHydKJaMs0R8RifFswa9RW36sD9MeL4+kREJsEUQbS0LxlpueORtpCsvEhq4x7HqkJKkj8I9n/MABwdI0p1mKQ==","sha1":"66916c08686b3fa669e5d2667ff3805ebabe6a1e"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/intl-ads/MAL-2026-4587.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}]}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"}]}