{"id":"MAL-2026-5413","summary":"Malicious code in @klapp-login-platform/native-sdk (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (3b3bc8633d15b44abc90074d3362fd9399f53d10a88e24264caee9d924a72bb6)\nOn `npm install`, the package's `preinstall` lifecycle hook runs `node index.js`, which collects installer-side identifiers — `os.hostname()`, `os.userInfo().username`, `__dirname`, `process.cwd()`, and the package name — and exfiltrates them through two channels. First, the JSON payload is hex-encoded into DNS labels and resolved under `*.d8jbmnsqcfu78dfs8vdg34ohqhirb4pbg.oast.live`, an out-of-band collector. Second, the same JSON is POSTed to a bare IP `http://172.201.213.59:9090/c`. Neither destination matches any documented vendor SDK endpoint. The package metadata reinforces malicious intent: the scope `@klapp-login-platform` resembles an internal namespace, the description is `security research`, and the version `99.0.2` is inflated to win dependency-confusion resolution against a private package. Installing the package immediately leaks host identity to attacker-controlled infrastructure.\n","modified":"2026-06-09T19:01:29.268956368Z","published":"2026-06-09T17:35:09Z","database_specific":{"malicious-packages-origins":[{"versions":["99.0.2"],"source":"amazon-inspector","sha256":"3b3bc8633d15b44abc90074d3362fd9399f53d10a88e24264caee9d924a72bb6","import_time":"2026-06-09T17:45:52.557225152Z","id":"IN-MAL-2026-005069","modified_time":"2026-06-09T17:35:09Z"},{"versions":["99.0.2"],"source":"amazon-inspector","sha256":"4ae85072d8a51ca0d5080df8308f6bdc17112f8245cb5524e8419bb7dadf71bf","import_time":"2026-06-09T17:45:52.604032739Z","id":"IN-MAL-2026-005070","modified_time":"2026-06-09T17:35:09Z"},{"versions":["99.0.0"],"source":"amazon-inspector","sha256":"1a1c21c478fd309e16577b1d023bcc82834075d2b8f6b27ef867764c7db7c3f6","import_time":"2026-06-09T18:50:17.819553446Z","id":"IN-MAL-2026-005126","modified_time":"2026-06-09T17:50:20Z"},{"modified_time":"2026-06-09T17:50:20Z","versions":["99.0.0"],"source":"amazon-inspector","sha256":"e8695fc1070f506a7aba7fc8895f25d14477e685da821196df6b59b027b65db0","import_time":"2026-06-09T18:50:17.877710262Z","id":"IN-MAL-2026-005127"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@klapp-login-platform/native-sdk/v/99.0.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@klapp-login-platform/native-sdk/v/99.0.0"}],"affected":[{"package":{"name":"@klapp-login-platform/native-sdk","ecosystem":"npm","purl":"pkg:npm/%40klapp-login-platform%2Fnative-sdk"},"versions":["99.0.2","99.0.0"],"database_specific":{"indicators":{"evidence_files":[{"path":"index.js","sha256":"c1db02bd41e4eb1d1b347f54a8eae90ed9e44805a5d4a34d04a85bdcb76e4c02","tlsh":"e0f00ce162b0d0fd8b708580ecd4668092b7c252b00288f4dc8d0ece0ac28e05d76ab1"},{"sha256":"8f45118b065eba7acc7aae228595a6e7f47dcdc796de12119a3dc64b9705d1d3","tlsh":"77d022380b31b83a076143f0acb6ac8ca0f8c31840808d1c4de740b485b17f8809d022","path":"package.json"}],"package_integrity":[{"filename":"native-sdk-99.0.2.tgz","hashes":{"sha512_sri":"sha512-5esJ3UjfeZDD/DyriKAPZhHaQ55CYetibREKimT+VSc3VZ/ZRZBT3UWGBMJcz4IfpuzAfwKLoXRm5ZpU1DrcmQ==","sha1":"ffea4b3118588a5c1602e95551c5a0cdfc2eb2ff"}}],"domains":["7b2268223a227363616e2d386234653036633064633634222c2275223a22.7363616e222c2264223a222f686f6d652f7363616e2f6e6f64655f6d6f64.756c65732f406b6c6170702d6c6f67696e2d706c6174666f726d2f6e6174.d8jbmnsqcfu78dfs8vdg34ohqhirb4pbg.oast.live"]},"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@klapp-login-platform/native-sdk/MAL-2026-5413.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}