{"id":"MAL-2026-5520","summary":"Malicious code in @access-risk/browser-remedy-react (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (0de4bc9f19feea718e091e9b0a480e9b939cdffa88109375020895c99efa489c)\nOn `npm install`, postinstall.js executes automatically and collects host identity and environment details using `os.hostname()`, `process.cwd()`, and filesystem reads, base64-encodes the data via `Buffer.from(...).toString('base64')`, and exfiltrates it through both DNS lookups (`require('dns')`) and HTTPS requests (`require('https')`). The dual-channel base64 exfiltration shape (DNS tunneling plus HTTPS POST) combined with collection of system identifiers is the canonical install-time data-theft fingerprint and provides direct attacker benefit: any machine running `npm install` for this package leaks identifying information to an external destination automatically, before the user has reviewed any package code.\n","modified":"2026-06-10T19:31:30.525173479Z","published":"2026-06-10T18:26:58Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-06-10T19:23:47.938500349Z","modified_time":"2026-06-10T18:26:58Z","sha256":"0de4bc9f19feea718e091e9b0a480e9b939cdffa88109375020895c99efa489c","source":"amazon-inspector","versions":["99.1.1"],"id":"IN-MAL-2026-005284"},{"id":"IN-MAL-2026-005285","import_time":"2026-06-10T19:23:48.013669047Z","modified_time":"2026-06-10T18:26:58Z","sha256":"22983c18e4a01fe9480967291bc8310bcf231043926db46d1a744c79cf1f85a6","source":"amazon-inspector","versions":["99.1.1"]},{"versions":["99.0.0"],"id":"IN-MAL-2026-005287","import_time":"2026-06-10T19:23:48.219525947Z","modified_time":"2026-06-10T18:27:31Z","sha256":"9556d538cc707208472ce3125a1a1355360126cf001957d2335ca5f4596a7e8a","source":"amazon-inspector"},{"source":"amazon-inspector","versions":["99.0.0"],"id":"IN-MAL-2026-005286","import_time":"2026-06-10T19:23:48.116490955Z","modified_time":"2026-06-10T18:27:31Z","sha256":"a31321d1ff1c689bc766a4c0c6cbe3419e4e3d9f05be465a59ce8e20d2ccab2c"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@access-risk/browser-remedy-react/v/99.1.1"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/@access-risk/browser-remedy-react/v/99.0.0"}],"affected":[{"package":{"name":"@access-risk/browser-remedy-react","ecosystem":"npm","purl":"pkg:npm/%40access-risk%2Fbrowser-remedy-react"},"versions":["99.1.1","99.0.0"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"domains":["wybqtvzmfhssbvhokfgbwtb4j5mlyejnl.oast.fun","7363616e2d3965333130346234366537312e7363616e.wybqtvzmfhssbvhokfgbwtb4j5mlyejnl.oast.fun"],"evidence_files":[{"sha256":"9847baf3c44dd9ad67385f95bee607ec5f6677f179c361aa56f9a50e8341414a","tlsh":"763162e112f4e2205b7be0c4f96a9c569163e203710bede0f64c02651fc56b494b24f9","path":"postinstall.js"}],"package_integrity":[{"filename":"browser-remedy-react-99.1.1.tgz","hashes":{"sha1":"c53b97a2fd46a4f42897f6d07ebf38eb31ddba4a","sha512_sri":"sha512-pnjcis5DMVunnY2aloPghdvomcSj8aMPzYLnav+YAzy1iNkB0tVbY2jOmFhoRdb3TY38S22u7ht1JIQqxh3dhQ=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@access-risk/browser-remedy-react/MAL-2026-5520.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}