{"id":"MAL-2026-5417","summary":"Malicious code in @klapp-sca/routes (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (495f510483f297a56d545e8555db20eb54569f904bfd71853e54a18d89812cb0)\npackage.json declares `\"preinstall\": \"node index.js || true\"`, so on every `npm install` the bundled index.js runs automatically and collects os.hostname(), os.userInfo().username, __dirname, and process.cwd() into a JSON payload. The payload is hex-encoded into DNS labels and resolved against `*.d8jbmnsqcfu78dfs8vdg34ohqhirb4pbg.oast.live` (an Interactsh/Burp-Collaborator-style out-of-band DNS sink) and simultaneously POSTed to a hardcoded bare IP at `http://172.201.213.59:9090/c`. This is a classic install-time reconnaissance beacon: installer machine identity is leaked to attacker-controlled infrastructure without any consent or user action beyond installing the package. The package's stated 'security research' description does not change the impact — any installer that runs `npm install` has their hostname, username, and working-directory paths sent to third-party endpoints.\n","modified":"2026-06-09T19:01:27.916744086Z","published":"2026-06-09T17:35:47Z","database_specific":{"malicious-packages-origins":[{"sha256":"11ae6419c673fc32db76632ea472b0a5c4fdb0beff999d5e6cd8fc144abab562","import_time":"2026-06-09T17:45:53.046415938Z","id":"IN-MAL-2026-005077","modified_time":"2026-06-09T17:35:47Z","versions":["99.0.1"],"source":"amazon-inspector"},{"source":"amazon-inspector","sha256":"495f510483f297a56d545e8555db20eb54569f904bfd71853e54a18d89812cb0","import_time":"2026-06-09T17:45:53.012672857Z","id":"IN-MAL-2026-005076","modified_time":"2026-06-09T17:35:47Z","versions":["99.0.1"]},{"modified_time":"2026-06-09T17:56:55Z","versions":["99.0.0"],"source":"amazon-inspector","sha256":"813b153ed59f9a72a56179d192cc44c350ee849ae13b02e6dd7ef36496fd9843","import_time":"2026-06-09T18:50:20.734099927Z","id":"IN-MAL-2026-005155"},{"id":"IN-MAL-2026-005154","modified_time":"2026-06-09T17:56:54Z","versions":["99.0.0"],"source":"amazon-inspector","sha256":"d896040967e9bedf9f3146daf8c14a5669d1cdb47b776a9b747d940be79c3c1e","import_time":"2026-06-09T18:50:20.609600129Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@klapp-sca/routes/v/99.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@klapp-sca/routes/v/99.0.0"}],"affected":[{"package":{"name":"@klapp-sca/routes","ecosystem":"npm","purl":"pkg:npm/%40klapp-sca%2Froutes"},"versions":["99.0.1","99.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@klapp-sca/routes/MAL-2026-5417.json","indicators":{"domains":["7b2268223a227363616e2d663162373062343163346266222c2275223a22.7363616e222c2264223a222f686f6d652f7363616e2f6e6f64655f6d6f64.756c65732f406b6c6170702d7363612f726f75746573222c2263223a222f.d8jbmnsqcfu78dfs8vdg34ohqhirb4pbg.oast.live"],"evidence_files":[{"path":"index.js","sha256":"bcf07e7256b008ece552b37047030f2158b716f33a457ebf0a3050b1974d4fe3","tlsh":"83f041e161b0d0f98b708580bdc86a8493b3c652b00288f0dc0d0fcf06c28d05c76ae1"},{"tlsh":"a0c0807c2d31b436176183f46d796c4cf1fdc61410d48d488fe6457454b1be8905e115","path":"package.json","sha256":"4a38501e831ae72159f7200052b4165637cef0e5f4288f19b2e9198f42eae850"}],"package_integrity":[{"filename":"routes-99.0.1.tgz","hashes":{"sha1":"17e6606e34e4526991637c674335e4900207b0f2","sha512_sri":"sha512-k58XPdHNrB4Gu9yAjc40fSqHvEgLpyanUKlvUfHezEHLCltndHWgMRMyLGppkElq72vXE1+CcAAN6ifm8jAKjQ=="}}]},"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}