{"id":"MAL-2026-5427","summary":"Malicious code in @payment-review/store (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (2d624eaefbb0245bf0c9a7b598c461a3ba5ec48005cfec223898062741ef8c2e)\npackage.json declares `preinstall: node index.js || true`, so installing the package automatically runs index.js on `npm install`. The script collects host identity fields — `os.hostname()`, `os.userInfo().username`, `__dirname`, `process.cwd()`, and the package id — serializes them as JSON, and exfiltrates them via two channels: (1) an HTTP POST to the hardcoded bare IP `http://172.201.213.59:9090/c`, and (2) a hex-encoded DNS resolution against a subdomain of `d8jbmnsqcfu78dfs8vdg34ohqhirb4pbg.oast.live` (Interactsh out-of-band exfiltration). The package metadata (`@payment-review/store`, version `99.0.0`, description `security research`, no real functionality) matches the dependency-confusion shape: a high version number under a target-org-styled scope intended to override an internal private package of the same name. Installing this package leaks the installer's host and user identity to attacker-controlled infrastructure with no user consent.\n","modified":"2026-06-09T19:01:27.914333152Z","published":"2026-06-09T17:36:12Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-06-09T17:45:53.365719911Z","id":"IN-MAL-2026-005081","modified_time":"2026-06-09T17:36:13Z","versions":["99.0.1"],"source":"amazon-inspector","sha256":"0d4410dd7531b8073ca94b67e1f378c1384acfe969b9b8a12ed934be962b1565"},{"import_time":"2026-06-09T17:45:53.304444681Z","id":"IN-MAL-2026-005080","modified_time":"2026-06-09T17:36:12Z","versions":["99.0.1"],"source":"amazon-inspector","sha256":"16277824e707bfa5d164fe338408172b64a7e3c02ee6669b1391b8ad1ae41965"},{"import_time":"2026-06-09T18:50:18.729919262Z","id":"IN-MAL-2026-005137","modified_time":"2026-06-09T17:52:39Z","versions":["99.0.0"],"source":"amazon-inspector","sha256":"98ffd07a5d66d1101647686e7de8afd31b09a0af01aa3118a9de460089751408"},{"id":"IN-MAL-2026-005136","modified_time":"2026-06-09T17:52:39Z","versions":["99.0.0"],"source":"amazon-inspector","sha256":"2d624eaefbb0245bf0c9a7b598c461a3ba5ec48005cfec223898062741ef8c2e","import_time":"2026-06-09T18:50:18.669508796Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@payment-review/store/v/99.0.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@payment-review/store/v/99.0.0"}],"affected":[{"package":{"name":"@payment-review/store","ecosystem":"npm","purl":"pkg:npm/%40payment-review%2Fstore"},"versions":["99.0.1","99.0.0"],"database_specific":{"indicators":{"evidence_files":[{"tlsh":"1cf0e1e161a1d0f99f719590bdd4a68457b3d656b04288f0ec5d0fcf06c28e05d76ae1","path":"index.js","sha256":"900eae6f9d233e1b556d274405ce0d0b0db6ca9226c20dd086b89fd9e10739f8"},{"tlsh":"42c012683d21f8361ea382f06d76ac4d71f9821450c44c049af2417855b1be881ad116","path":"package.json","sha256":"e860ba47ac1a906170d932fc95a8f03abd6b38e1f79bc4da389317e9fb0cfe3c"}],"package_integrity":[{"hashes":{"sha1":"6030bf93b030307d2448b229d0f84f1fb08daece","sha512_sri":"sha512-SKulMQis2tMI/UQpoauTwxKbpizCMUBaqCEmqfmWOAeIqW5p4m8vCiMKSfjL6aFq2zx/2lDFW/OMnyWehF8HTQ=="},"filename":"store-99.0.1.tgz"}],"domains":["7b2268223a227363616e2d616630666131346534626133222c2275223a22.7363616e222c2264223a222f686f6d652f7363616e2f6e6f64655f6d6f64.756c65732f407061796d656e742d7265766965772f73746f7265222c2263.d8jbmnsqcfu78dfs8vdg34ohqhirb4pbg.oast.live"]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@payment-review/store/MAL-2026-5427.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}