{"id":"MAL-2026-5425","summary":"Malicious code in @oplus/obus-web-sdk (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (956ecc19633177f7ef9b458e6407ffbba6c8366688249c07bfd7f3c8e85c17a9)\nOn `npm install`, the package's `scripts/postinstall.js` collects the installer's username (`os.userInfo()`), hostname (`os.hostname()`), current working directory (`process.cwd()`), and public IP (fetched from `https://api.ipify.org`), then exfiltrates the data to a hardcoded interactsh C2 subdomain `xjaipnfhcpawuhzlgzkzo1ak3aai9m873.oast.fun` through two channels: a DNS lookup with the hex-encoded payload as a subdomain, and an HTTPS GET to `/poc` carrying the data base64-encoded in an `x-poc` header. The package uses the `@oplus` scope (impersonating OPlus/Oppo internal namespaces) and is published at version `99.99.99` — the canonical dependency-confusion pattern designed to outrank any legitimate internal release during resolution. The in-source comment framing this as a benign PoC does not change the installer-side harm: any build that resolves `@oplus/obus-web-sdk` against the public registry will leak host/user/IP/cwd to attacker infrastructure.\n","modified":"2026-06-09T18:01:32.552316734Z","published":"2026-06-09T17:16:38Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-06-09T17:16:39Z","sha256":"870118deab21abae390aabf8c29ffc8e0b29bb14fa1ebc9d66b5c673c5680e12","source":"amazon-inspector","versions":["99.99.99"],"id":"IN-MAL-2026-005007","import_time":"2026-06-09T17:45:48.489808916Z"},{"sha256":"956ecc19633177f7ef9b458e6407ffbba6c8366688249c07bfd7f3c8e85c17a9","source":"amazon-inspector","versions":["99.99.99"],"id":"IN-MAL-2026-005006","import_time":"2026-06-09T17:45:48.457399799Z","modified_time":"2026-06-09T17:16:38Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@oplus/obus-web-sdk/v/99.99.99"}],"affected":[{"package":{"name":"@oplus/obus-web-sdk","ecosystem":"npm","purl":"pkg:npm/%40oplus%2Fobus-web-sdk"},"versions":["99.99.99"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"domains":["api.ipify.org"],"evidence_files":[{"tlsh":"dd1102e862f0932401b250c8c8abdd0a4117e1137646e894facc41949f456b8ecf29f9","path":"scripts/postinstall.js","sha256":"22d9555e398870d0fdccbe756f7a84e1fe5055f70ad874a490c8b2008a03241c"},{"tlsh":"20d022542c04a33339cd06af0836d808b1a98e4ef344b8184bc301c0d30a3facea6b26","path":"package.json","sha256":"cda1e66202206525342bb97d5f3a0df2252897cc4e9e8c2c9bccdecef36eb9e7"}],"package_integrity":[{"hashes":{"sha1":"77a3f64cf26e35dbb54f169660ada1f5ea5048c4","sha512_sri":"sha512-azu+JHGRqklsQEk2xXpu2Yq488zkNwOErBCLy7Leu66dp9EhZwDxDqdspFjzRJiTPoxmA+d1+on/I9jkv+nN/g=="},"filename":"obus-web-sdk-99.99.99.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@oplus/obus-web-sdk/MAL-2026-5425.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}