{"id":"MAL-2026-5441","summary":"Malicious code in exodus-secure-container (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (92bc77b12251baa18392bd90e84d6bdc57aaef9a8c774f8cb29a0066e80f76b5)\nOn `npm install`, the package runs `node src/canary.js` as a postinstall hook. That script performs a DNS lookup and HTTPS GET to the hardcoded host `96e03fa6c292469a-172-245-86-254.serveousercontent.com/c` — an anonymous serveo.net reverse-tunnel endpoint, not a publisher CDN. The beacon fires unconditionally on every install, signalling the installer's public IP and DNS-resolver identity to a third-party host. The package itself has no functionality: `src/index.js` is `module.exports = {}`, and the version `99.0.0-canary.1` is engineered to win semver resolution against an internal package of the same name (dependency-confusion canary shape). Whether the operator is a researcher or a hostile actor, any environment that resolves this name against the public registry leaks install-time identity to an attacker-controllable tunnel.\n","modified":"2026-06-09T18:01:35.961726367Z","published":"2026-06-09T17:43:58Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-005106","import_time":"2026-06-09T17:45:54.950731498Z","modified_time":"2026-06-09T17:43:58Z","sha256":"8ed2337fdd749accb1f4a5b190413ced8c1cd0f1b691ba3e79dd4bfe9a3f3ef8","source":"amazon-inspector","versions":["99.0.0-canary.1"]},{"id":"IN-MAL-2026-005105","import_time":"2026-06-09T17:45:54.915982601Z","modified_time":"2026-06-09T17:43:58Z","sha256":"92bc77b12251baa18392bd90e84d6bdc57aaef9a8c774f8cb29a0066e80f76b5","source":"amazon-inspector","versions":["99.0.0-canary.1"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/exodus-secure-container/v/99.0.0-canary.1"}],"affected":[{"package":{"name":"exodus-secure-container","ecosystem":"npm","purl":"pkg:npm/exodus-secure-container"},"versions":["99.0.0-canary.1"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"domains":["96e03fa6c292469a-172-245-86-254.serveousercontent.com"],"evidence_files":[{"path":"src/canary.js","sha256":"07b1338d03a1c6e986a4c5961cb218c2e795d1ba30740c2b3581aff8a1ca520e","tlsh":"bed022fe91c8080aa3a047ac841a60cab94bc9f8008485d2730c86d220c0aeea2ac238"},{"tlsh":"3ec08c482900553f0a9486fb5c75e88c42bc975222d49c28d6a221b580a0bea9b57062","path":"package.json","sha256":"782df5d0a2bd69ec6426ae8d5416d2fdda1bf3d43701cd70cec54b4b5cc105ac"}],"package_integrity":[{"filename":"exodus-secure-container-99.0.0-canary.1.tgz","hashes":{"sha1":"03c9a9f1989e1d05b4b09a51a742b09c78ce59c9","sha512_sri":"sha512-98RdMze8YU6U39PxGMg+/OuDhJ8wRvgW5O/3P5aTvn7t3AOIQd6Gbh9qKYA7B0L8fsCH75oA2PNijin/2q76Cg=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/exodus-secure-container/MAL-2026-5441.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}