{"id":"MAL-2026-5327","summary":"Malicious code in @listings/energy-labels (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (41caac3ab1f9c35a72841357174aeeec16c142c08cc28030a875b2dba85f04ba)\nThe package declares `\"preinstall\": \"node index.js || true\"` in package.json, so on every `npm install` the script executes automatically and silently swallows errors. index.js collects host identity (os.hostname(), os.userInfo().username, __dirname, process.cwd(), package label), hex-encodes the JSON payload as a DNS subdomain of `d8jbmnsqcfu78dfs8vdg34ohqhirb4pbg.oast.live` (an out-of-band interaction service used for exfiltration), and additionally POSTs the same payload over plain HTTP to a hardcoded bare IP `http://172.201.213.59:9090/c`. There is no TLS, no authentication, no documented purpose, and the bare-IP plus OOB DNS pattern is consistent with dependency-confusion / supply-chain reconnaissance infrastructure. Installer machines are fingerprinted and reported to the attacker on install with no user consent.\n\n## Source: ossf-package-analysis (4df629d1450770515d9dc9346d52b9b728dbaab01bbf64a4bb5c17563dcc6991)\nThe OpenSSF Package Analysis project identified '@listings/energy-labels' @ 99.0.1 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n","modified":"2026-06-09T19:01:27.907597288Z","published":"2026-06-08T14:00:52Z","database_specific":{"malicious-packages-origins":[{"source":"ossf-package-analysis","sha256":"4df629d1450770515d9dc9346d52b9b728dbaab01bbf64a4bb5c17563dcc6991","import_time":"2026-06-08T15:12:42.589102064Z","modified_time":"2026-06-08T14:00:52Z","versions":["99.0.1"]},{"sha256":"c7a6ad6a5c1f36077f116e189769ad92bac4bfeecb7a893df22cbc71577d3142","import_time":"2026-06-09T17:45:53.94471214Z","id":"IN-MAL-2026-005088","modified_time":"2026-06-09T17:38:58Z","versions":["99.0.1"],"source":"amazon-inspector"},{"source":"amazon-inspector","sha256":"41caac3ab1f9c35a72841357174aeeec16c142c08cc28030a875b2dba85f04ba","import_time":"2026-06-09T18:50:18.473571737Z","id":"IN-MAL-2026-005134","modified_time":"2026-06-09T17:50:48Z","versions":["99.0.0"]},{"versions":["99.0.0"],"source":"amazon-inspector","sha256":"74d56d725efc1fa5aeb50fa7308a150e4a7b84357445a6d097ed3ea73b31fbc7","import_time":"2026-06-09T18:50:18.591324887Z","id":"IN-MAL-2026-005135","modified_time":"2026-06-09T17:50:49Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@listings/energy-labels/v/99.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@listings/energy-labels/v/99.0.0"}],"affected":[{"package":{"name":"@listings/energy-labels","ecosystem":"npm","purl":"pkg:npm/%40listings%2Fenergy-labels"},"versions":["99.0.1","99.0.0"],"database_specific":{"indicators":{"evidence_files":[{"path":"index.js","sha256":"bd4bb91e5e7adbf72abe489a837745c3b43a06f03bcd96a205a2f1cebfd64fed","tlsh":"61f00ce121a0d4bdcba09580bc84768862b3c642b00288f0dc4d0ece0ac28d05c769a1"}],"package_integrity":[{"filename":"energy-labels-99.0.1.tgz","hashes":{"sha512_sri":"sha512-L+wnCLVnIwC88IdOfP9z5h6HMDJxgKeKrkEpkWpERSkDvuTgDa+1K3uByQMnU6+pYRqNbYCZNf2iBeGrQD/ecg==","sha1":"cef6520476e38ed5a8c15cb1619f90285a1b29f6"}}],"domains":["7b2268223a227363616e2d323564316132343163326331222c2275223a.d8jbmnsqcfu78dfs8vdg34ohqhirb4pbg.oast.live"]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@listings/energy-labels/MAL-2026-5327.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}