{"id":"MAL-2026-6349","summary":"Malicious code in bug-monorepo (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (bdac6ea5e7530323f39451c43fc9e4693b30704a5f9e9287018c727a44c36a5d)\npackage.json declares `preinstall: node index.js`, causing index.js to run automatically on `npm install`. The script collects hostname, username, home directory, DNS servers, and the full package.json, and reads `/etc/passwd` and `/etc/hosts` (index.js:18), then HTTPS-POSTs the JSON payload to `cp5uzinglyy3ifb8gvvgvq5qvh19p0dp.oastify.com` (a Burp Collaborator out-of-band subdomain controlled by the attacker). Empty author/description fields and the generic `bug-monorepo` name are consistent with a dependency-confusion recon package targeting an internal namespace. Installing this package leaks host identity and sensitive system file contents to an attacker-controlled endpoint.\n","modified":"2026-06-23T22:46:24.948340980Z","published":"2026-06-23T21:53:55Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-007383","import_time":"2026-06-23T22:31:28.207528469Z","modified_time":"2026-06-23T21:53:55Z","sha256":"bdac6ea5e7530323f39451c43fc9e4693b30704a5f9e9287018c727a44c36a5d","source":"amazon-inspector","versions":["3.1.94"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/bug-monorepo/v/3.1.94"}],"affected":[{"package":{"name":"bug-monorepo","ecosystem":"npm","purl":"pkg:npm/bug-monorepo"},"versions":["3.1.94"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"sha256":"ccdd4129bddff8b06992b21c85a3a541a4bdf008d6f00cb5252dcc252387c14a","tlsh":"3c411199a2ca17330dd250c06a0c70852359fa777269e8d076cf43969f869f8b7226f3","path":"index.js"},{"path":"package.json","sha256":"afdc2a55f1e788e26ecb3362af7222937ab658332826fc22becf6e43867bb558","tlsh":"f7d0a7304ea1553375c116920c2b949772618f2f04543c0863cf292c85ce3b798ff30d"}],"package_integrity":[{"filename":"bug-monorepo-3.1.94.tgz","hashes":{"sha1":"00905432faa6a3cec56090e429181ef2171ac3af","sha512_sri":"sha512-lrhFdjjEkzV9Np6ZzcKl0ewzGPDFobymHFwxjhdUgBIXXtHxEm9eIdTNdeuTjUoPISArl160UJIwDdlBVrxXig=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bug-monorepo/MAL-2026-6349.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}