{"id":"MAL-2026-6263","summary":"Malicious code in gd-auth-client (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (4de00613e21b42bf3c651995beae63ff9d85772b9370145152d172a062be4fb7)\npackage.json declares `preinstall: node index.js`, which runs automatically on `npm install`. index.js requires os, dns, https, querystring, and the local package.json, then collects installer host identifiers — homedir (os.homedir()), hostname (os.hostname()), username (os.userInfo().username), configured DNS servers (dns.getServers()), current working directory (__dirname), and the full package.json contents — and POSTs them via HTTPS to `6pwzxcku93yjz1m1mp1ctzofj6pxdn1c.oastify.com/dependency-confusion`, a Burp Collaborator (OAST) subdomain controlled by the publisher. The version number 999.0.0 combined with a generic, unscoped name is the standard dependency-confusion shape: the package is published to the public registry to win resolution against an internal/private package of the same name in a victim's build, at which point the preinstall hook beacons home with environment fingerprints suitable for follow-up targeting. Any developer or CI system that resolves this package suffers immediate exfiltration of host identity to an attacker-controlled endpoint at install time.\n","modified":"2026-06-22T16:46:23.777379355Z","published":"2026-06-22T16:26:57Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-06-22T16:36:58.565120185Z","modified_time":"2026-06-22T16:26:57Z","sha256":"4de00613e21b42bf3c651995beae63ff9d85772b9370145152d172a062be4fb7","source":"amazon-inspector","versions":["999.0.0"],"id":"IN-MAL-2026-007106"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/gd-auth-client/v/999.0.0"}],"affected":[{"package":{"name":"gd-auth-client","ecosystem":"npm","purl":"pkg:npm/gd-auth-client"},"versions":["999.0.0"],"database_specific":{"indicators":{"package_integrity":[{"filename":"gd-auth-client-999.0.0.tgz","hashes":{"sha1":"4f8218e16850f9bb7751fa1ce16dfd9fe984dc2b","sha512_sri":"sha512-BJ7hPRXSGGd7pmQ9nUAqzXIOHRI7Fk6p7+5ZeOzVwzEjihwoNM6IT1ovyTEb5EktCJGdS1t5TKYPfP215roU3A=="}}],"evidence_files":[{"sha256":"7da3dca20f9c2c55cfc4d0c35a6508da522dc6b051b540113f4c041e7cd07bbf","tlsh":"d311bde8519173640d7549d078a8e0089affeb74b60b4de8d5c906d45386af510b36e2","path":"index.js"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/gd-auth-client/MAL-2026-6263.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}]}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}