{"id":"MAL-2026-6268","summary":"Malicious code in zomato-core (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (d5042b2ca8b8b3ba1f073344762615dc532864913af3f54a16540d44dde97ba5)\npackage.json declares a preinstall lifecycle hook that runs curl to POST the installer's hostname, whoami output, current working directory, and the entire base64-encoded process environment to http://d8s0b82plbq3u5sb2vo0sb3a9obr4yjt7.oast.site/install/\u003cbase64-package-name\u003e over plaintext HTTP. This fires automatically on `npm install` with no user opt-in, leaking host identity and any secrets present in environment variables (CI tokens, AWS/GCP credentials, npm publish tokens, etc.). The package has no functional content — index.js is a one-line stub exporting `{ name: 'zomato-core', version: '1.0.0' }` — so the package exists solely as the exfiltration vehicle. The name and description impersonate an internal Zomato namespace (`zomato-core`, described as 'Zomato core utility library', repository `github.com/zomato/zomato-core`), consistent with a dependency-confusion attack against Zomato engineers and CI whose private internal `zomato-core` may resolve to this public registry copy.\n","modified":"2026-06-22T18:31:22.526805293Z","published":"2026-06-22T17:42:28Z","database_specific":{"malicious-packages-origins":[{"versions":["1.0.0"],"id":"IN-MAL-2026-007145","import_time":"2026-06-22T18:25:28.604462605Z","modified_time":"2026-06-22T17:42:28Z","sha256":"d5042b2ca8b8b3ba1f073344762615dc532864913af3f54a16540d44dde97ba5","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/zomato-core/v/1.0.0"}],"affected":[{"package":{"name":"zomato-core","ecosystem":"npm","purl":"pkg:npm/zomato-core"},"versions":["1.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/zomato-core/MAL-2026-6268.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"package_integrity":[{"filename":"zomato-core-1.0.0.tgz","hashes":{"sha1":"eefce3d6f8b52e566aea704e1b4bcfbba9e8578e","sha512_sri":"sha512-5JUXBGS8kWcAVQ66kO54xdxgJ9NskRBgIQJeFOFtGys4MjaEnN+7hNIXDKyeTyebWe+U4X95aaLR4BvFTMf9fA=="}}],"evidence_files":[{"path":"package.json","sha256":"e79ed065ff7dd48d6176435c1c651b99176ee2de3bdd3a027d817e8fddb9cb83","tlsh":"0e01fd78783496333fcc0271bd5a002d3c65bf0f84742c006e9b051d86cf219226d72a"}]}}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}