{"id":"MAL-2026-6252","summary":"Malicious code in zomato-logger (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (3dccb8b8b32337c2a257a763c273e03367ec07c904b5db0c07dbf514d546709d)\nOn `npm install`, the package's preinstall lifecycle script in package.json runs curl to POST the installer's hostname, current user (whoami), working directory, and the entire environment (base64-encoded `env` output) to http://d8s0b82plbq3u5sb2vo0sb3a9obr4yjt7.oast.site/install/\u003cbase64-pkg\u003e over plain HTTP. The destination is an Interactsh / oast.site out-of-band collaborator subdomain — infrastructure used to capture exfiltrated data from victim hosts. The package itself is a hollow stub (index.js exports only `{ name, version }`), and the metadata (`description: \"Zomato logging library\"`, repo URL git+https://github.com/zomato/zomato-logger.git) impersonates Zomato, consistent with a dependency-confusion attack targeting an org-internal package name. Any host that resolves and installs this package leaks every environment variable (including any CI secrets, tokens, and credentials present in the build environment) to the attacker.\n\n## Source: ossf-package-analysis (637e09431107722f9603562638df114fcb31994e21ead800ccd63a666f65bea3)\nThe OpenSSF Package Analysis project identified 'zomato-logger' @ 1.0.0 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n\n- The package executes one or more commands associated with malicious behavior.\n","modified":"2026-06-22T18:31:22.626345185Z","published":"2026-06-21T16:11:10Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-06-21T16:38:02.926477946Z","modified_time":"2026-06-21T16:11:10Z","versions":["1.0.0"],"source":"ossf-package-analysis","sha256":"637e09431107722f9603562638df114fcb31994e21ead800ccd63a666f65bea3"},{"sha256":"3dccb8b8b32337c2a257a763c273e03367ec07c904b5db0c07dbf514d546709d","import_time":"2026-06-22T18:25:28.525039494Z","id":"IN-MAL-2026-007144","modified_time":"2026-06-22T17:42:27Z","versions":["1.0.0"],"source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/zomato-logger/v/1.0.0"}],"affected":[{"package":{"name":"zomato-logger","ecosystem":"npm","purl":"pkg:npm/zomato-logger"},"versions":["1.0.0"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"path":"package.json","sha256":"90b50c56b7ef712957f85e5fd0d8925b745a2825e7dffd42f4ff712483421ec9","tlsh":"b40189287a3896237d8c4670bd5605293c657f8f84356c045edb111e82cf215226f626"}],"package_integrity":[{"hashes":{"sha1":"57015126cc539add7fc1738bf32499fb72b75603","sha512_sri":"sha512-jyTIli6O2+3yJxXICoR6XV9ZPL0qNo0Rj/Sw3zo63zUpLqDYQ7Kwey0BqBJ1nfO+igAN1U+VD6zbkDmuT5kd3A=="},"filename":"zomato-logger-1.0.0.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/zomato-logger/MAL-2026-6252.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}