{"id":"MAL-2026-6251","summary":"Malicious code in zomato-config (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (3a1b48a397992964f8f3982dc69a33431bfb26c911c29a1e5d124581cef46a40)\nDependency-confusion package targeting an internal Zomato namespace. The package ships only a stub index.js (`module.exports = { name: 'zomato-config', version: '1.0.0' }`) with no real functionality. Its package.json `preinstall` lifecycle hook runs `curl` to POST `hostname`, `whoami`, `pwd`, and the full process environment (base64-encoded via `env | base64 -w0`) to `http://d8s0b82plbq3u5sb2vo0sb3a9obr4yjt7.oast.site/install/...`. This fires automatically on `npm install` and leaks any environment-variable secrets present at install time (CI tokens, cloud credentials, npm/GitHub tokens) to an attacker-controlled out-of-band interaction host. The shape (empty payload + recon beacon to oast.site + internal-sounding name) matches a dependency-confusion reconnaissance / exfiltration package.\n\n## Source: ossf-package-analysis (4e8030ae84d02e1ee751b187b393636548810d1142b9272c85efc7f6bf030629)\nThe OpenSSF Package Analysis project identified 'zomato-config' @ 1.0.0 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n\n- The package executes one or more commands associated with malicious behavior.\n","modified":"2026-06-22T18:31:23.774065220Z","published":"2026-06-21T16:01:08Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-06-21T16:38:02.755200268Z","modified_time":"2026-06-21T16:01:08Z","versions":["1.0.0"],"source":"ossf-package-analysis","sha256":"4e8030ae84d02e1ee751b187b393636548810d1142b9272c85efc7f6bf030629"},{"versions":["1.0.0"],"source":"amazon-inspector","sha256":"3a1b48a397992964f8f3982dc69a33431bfb26c911c29a1e5d124581cef46a40","import_time":"2026-06-22T18:25:27.735548095Z","id":"IN-MAL-2026-007136","modified_time":"2026-06-22T17:16:21Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/zomato-config/v/1.0.0"}],"affected":[{"package":{"name":"zomato-config","ecosystem":"npm","purl":"pkg:npm/zomato-config"},"versions":["1.0.0"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"package_integrity":[{"hashes":{"sha1":"7c8160cd300c62c5e2093f30169d820cfa277836","sha512_sri":"sha512-S51H8R8jlBJeHVfQ7PG0XCDUgbmbZDytf3YqduB/9d7kPY+9FOAM7Xhs6EgX7Y8mAwrJ+ZrMNDD8EESAHKzRPg=="},"filename":"zomato-config-1.0.0.tgz"}],"evidence_files":[{"path":"package.json","sha256":"b9cb662899c45196d1099cd7fc5bda41b0a6a2d8d5526a316b7ccebf3b175441","tlsh":"8f01ce2678389a333e8c0a71fd96003d3c657f8f84361c046e6b151c828f219226e726"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/zomato-config/MAL-2026-6251.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}