{"id":"MAL-2026-5400","summary":"Malicious code in multica (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (d7d3e4277fb571072315c7f64c269029cd53c78b3ff27ec5536d748c659fd6a2)\nPackage is published at version 9999.99.99 with a description referencing an npm 404 in multica-ai/multica and a main module that recursively requires `multica` itself — the canonical shape of a dependency-confusion probe designed to win resolution against an internal package of the same name. On `npm install`, postinstall.js unconditionally POSTs a JSON payload containing the package name/version, Node version, OS platform, timestamp, detected CI vendor (selected from a list of 12 CI environment variables), and — when set — GITHUB_REPOSITORY, GITHUB_REPOSITORY_OWNER, and GITHUB_WORKFLOW to https://ddactic-lab.online/sc/beacon. A DNS fallback channel encodes a package slug, CI slug, and hash into a subdomain of b.ddactic-lab.online to bypass HTTP-blocking egress proxies. Installer harm: silent disclosure of internal package names, CI vendor, and GitHub org/repo/workflow identifiers to an attacker-controlled endpoint at install time, mapping which organizations resolve internal names to this public tarball.\n","modified":"2026-06-09T17:16:27.656094373Z","published":"2026-06-09T16:05:05Z","database_specific":{"malicious-packages-origins":[{"sha256":"d7d3e4277fb571072315c7f64c269029cd53c78b3ff27ec5536d748c659fd6a2","source":"amazon-inspector","versions":["9999.99.99"],"id":"IN-MAL-2026-004951","import_time":"2026-06-09T16:59:44.041464942Z","modified_time":"2026-06-09T16:05:05Z"},{"import_time":"2026-06-09T16:59:44.085919792Z","modified_time":"2026-06-09T16:05:06Z","sha256":"ece88aabcd1ebbdef6133024c757b2ce9efa038fabbce6d40ed87f9d60a3a735","source":"amazon-inspector","versions":["9999.99.99"],"id":"IN-MAL-2026-004952"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/multica/v/9999.99.99"}],"affected":[{"package":{"name":"multica","ecosystem":"npm","purl":"pkg:npm/multica"},"versions":["9999.99.99"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"package_integrity":[{"filename":"multica-9999.99.99.tgz","hashes":{"sha1":"1c7a0f237162d1e248b839e39e03a324ee840cd2","sha512_sri":"sha512-bBiQUUUXe9YheiHyratERQ3+jDvKi3n2on++cfjE4X8HJHaMamAjmNXbvJ5yncgDjWPfkj0l2P3fSQPVosMezA=="}}],"domains":["ddactic-lab.online","multica.none.eb9675bf.b.ddactic-lab.online","multica.none.eb9675bf.b.ddactic-lab.online.ec2.internal"],"evidence_files":[{"path":"postinstall.js","sha256":"e5c7efaa25bd6fc20c40fe6e39a40957043022e78b5ec6d9ad2b9e49a3ef75c8","tlsh":"e241a755829891340fe122c9b852c8165d7bd49633e799f0774d15226fc92bc03b2fdf"},{"path":"package.json","sha256":"4e023071425857ba2cdf256930249f55d85ad3a26d5dc7e7424ce219d792e126","tlsh":"95e0e5048d2067732ed836d5987a11c6b7720d0ba948bc2967a7001c87de9ab45be12a"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/multica/MAL-2026-5400.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}