{"id":"MAL-2026-5414","summary":"Malicious code in @klapp-login-platform/oidc (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (6c2b86b9675d4d22e101f4f10f521cc36069ecebd1680d4c3ecfa0c04e8169da)\nOn `npm install`, the package executes `node index.js` via its preinstall hook. index.js collects the installer's hostname (`os.hostname()`), username (`os.userInfo().username`), package directory (`__dirname`), and current working directory (`process.cwd()`), serializes them to JSON, hex-encodes the payload, and exfiltrates it through two channels: (1) a DNS resolution of a subdomain under `d8jbmnsqcfu78dfs8vdg34ohqhirb4pbg.oast.live` (interactsh-style out-of-band exfiltration), and (2) an HTTP POST to the bare IP `172.201.213.59:9090/c`. The package ships no documented functionality matching its `@klapp-login-platform/oidc` name; the description is 'security research'. The high version number (99.0.2) under an org-style scope on the public registry is consistent with a dependency-confusion attack designed to pre-empt resolution of an internal private package of the same name, and the beaconing payload provides the attacker with confirmation of which organizations have resolved the public version.\n","modified":"2026-06-09T19:01:29.433266331Z","published":"2026-06-09T17:35:15Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-06-09T17:45:52.783008124Z","id":"IN-MAL-2026-005072","modified_time":"2026-06-09T17:35:15Z","versions":["99.0.2"],"source":"amazon-inspector","sha256":"11ee7c03075e594b6e2853b480a25dcb21e349e929c5a0e9ce2d4a3893eb7931"},{"versions":["99.0.2"],"source":"amazon-inspector","sha256":"6c2b86b9675d4d22e101f4f10f521cc36069ecebd1680d4c3ecfa0c04e8169da","import_time":"2026-06-09T17:45:52.658354509Z","id":"IN-MAL-2026-005071","modified_time":"2026-06-09T17:35:15Z"},{"modified_time":"2026-06-09T17:49:43Z","versions":["99.0.0"],"source":"amazon-inspector","sha256":"d345e380cc2c86b2c8cb5578e657199a73d9627e6839459ada7b6e5eaba4cc24","import_time":"2026-06-09T18:50:17.734880471Z","id":"IN-MAL-2026-005125"},{"sha256":"fc2fae7737666daf215586b5c271c5266980f39ab734b7b043558203ce2f1080","import_time":"2026-06-09T18:50:17.541135555Z","id":"IN-MAL-2026-005124","modified_time":"2026-06-09T17:49:43Z","versions":["99.0.0"],"source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@klapp-login-platform/oidc/v/99.0.2"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@klapp-login-platform/oidc/v/99.0.0"}],"affected":[{"package":{"name":"@klapp-login-platform/oidc","ecosystem":"npm","purl":"pkg:npm/%40klapp-login-platform%2Foidc"},"versions":["99.0.2","99.0.0"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@klapp-login-platform/oidc/MAL-2026-5414.json","indicators":{"domains":["7b2268223a227363616e2d386630663633616136323435222c2275223a22.7363616e222c2264223a222f686f6d652f7363616e2f6e6f64655f6d6f64.756c65732f406b6c6170702d6c6f67696e2d706c6174666f726d2f6f6964.d8jbmnsqcfu78dfs8vdg34ohqhirb4pbg.oast.live"],"evidence_files":[{"path":"index.js","sha256":"db7379cc98c6fb55ceffe6b6d569db695b575c82d63857c6170366a1bc959c96","tlsh":"f1f00ce162b0d0f98b708980ecc4668053b7c252b00288e4dc0d0ecf0ac24e05d76aa1"},{"sha256":"a8451d05deeb1c1b6ebd492936e39ada28f20f877568ddf00742b06a23339099","tlsh":"4fc022380931b836076146f0a8b6ac4c61f8c25400808d0c4ee380b086b17e8809d002","path":"package.json"}],"package_integrity":[{"hashes":{"sha1":"85e2ef3c81d76a31daf1f93b0968e208a3cd8f24","sha512_sri":"sha512-LVt3lU0rfSxuLpIp2caRXan7Js9Bv79dtTsOnt+XCVyLZxt12oO4D9XVPTIegbaFoz4RmaPuROcmoB10ybVNRQ=="},"filename":"oidc-99.0.2.tgz"}]}}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}