{"id":"MAL-2026-4639","summary":"Malicious code in pg-expense-example (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (d1d939ad3f0e8e9754bf3562f06692713a76d5c0f18ac13c956f9cb199ed0fbf)\nOn require/load, index.js unconditionally collects host identifiers (hostname, username, platform, arch, cwd, pid) and sends them as URL query parameters via HTTPS GET to a hardcoded Burp Collaborator-style domain `vwfmeddcdgidvdwpkigkg0l8us5vf3wtx.oast.fun`. The package ships no advertised functionality — its only behavior on load is the beacon. package.json has empty author/description fields and declares an unused `chalk` dependency. A code comment in Azerbaijani (`sənin domenin` = 'your domain') is consistent with an attacker-controlled callback host, indicating PoC/reconnaissance malware rather than legitimate software.\n","modified":"2026-05-26T06:02:49.140669911Z","published":"2026-05-22T19:52:30Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-05-26T05:52:14.213435018Z","modified_time":"2026-05-22T19:52:30Z","sha256":"d1d939ad3f0e8e9754bf3562f06692713a76d5c0f18ac13c956f9cb199ed0fbf","source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-004250"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/pg-expense-example/v/1.0.0"}],"affected":[{"package":{"name":"pg-expense-example","ecosystem":"npm","purl":"pkg:npm/pg-expense-example"},"versions":["1.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"filename":"pg-expense-example-1.0.0.tgz","hashes":{"sha1":"f761064e0df6acf54fa877225239ff9adf5ce743","sha512_sri":"sha512-EK9Gl6R2zlVSPYxkexRYq9pxic444clddv4/pL1veSi2SmGTgMo2K0m40hz1Hf6B7ZTKkymE2AN0+Rt6xdikUw=="}}],"evidence_files":[{"path":"index.js","sha256":"b05da6ffb4b4d0de6b9ab5b2015f824eb727babe0be418b7191c42b8174d77ff","tlsh":"ca11eff5aaf385a01ebb21c05586580690afd5037d0df8fc7e9d43e00f854b545a1ab5"},{"path":"package.json","sha256":"96b2f35f8d04b83fc37ef142a6abd97123d03d94191c026457c8c85f4656a2cb","tlsh":"20e0c22859a2993305c612510d2d9053b261de1f0048bc0c63cb992c86de5b328fe75e"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/pg-expense-example/MAL-2026-4639.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"}]}