{"id":"MAL-2026-6458","summary":"Malicious code in wp-codebox-workspace (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (a44aa2030ed09d6ec3998c59953a44e013c1993d93a90ee031b0999480afb03c)\nPackage is published at version 9999.99.99 with a description referencing an 'npm 404 error referenced in Extra-Chill/homeboy-extensions' — the textbook dependency-confusion shape, where an unclaimed internal package name is registered publicly at a maximal version so private builds silently resolve to this public package. On install, postinstall.js reads npm package metadata, Node/OS info, and CI environment indicators including GITHUB_REPOSITORY, GITHUB_REPOSITORY_OWNER, and GITHUB_WORKFLOW, then POSTs them to https://ddactic-lab.online/sc/beacon. A DNS-lookup fallback encodes the package slug, CI provider, and a hash into a subdomain label under b.ddactic-lab.online, with an in-source comment stating the channel exists to fire 'even through HTTP-blocking corporate proxies' — explicit intent to evade installer egress controls. The combined effect: any private CI build that mistakenly resolves this name leaks the victim organization's private repository, owner, and workflow identifiers to an attacker-controlled host, with a covert DNS fallback for environments that block HTTP.\n","modified":"2026-06-25T08:01:27.123118534Z","published":"2026-06-25T07:26:37Z","database_specific":{"malicious-packages-origins":[{"source":"amazon-inspector","versions":["9999.99.99"],"id":"IN-MAL-2026-007507","import_time":"2026-06-25T07:47:52.732044788Z","modified_time":"2026-06-25T07:26:37Z","sha256":"a44aa2030ed09d6ec3998c59953a44e013c1993d93a90ee031b0999480afb03c"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/wp-codebox-workspace/v/9999.99.99"}],"affected":[{"package":{"name":"wp-codebox-workspace","ecosystem":"npm","purl":"pkg:npm/wp-codebox-workspace"},"versions":["9999.99.99"],"database_specific":{"indicators":{"package_integrity":[{"filename":"wp-codebox-workspace-9999.99.99.tgz","hashes":{"sha1":"4b0d86d4336e5e214442e956b868af27a1a08ca3","sha512_sri":"sha512-0Zxe6cpbv2drlgHveqXoaF3jjDzmYZR+M3aO7oE0ujVrp3cDcUfTOoVJ7ExfbWqwP9J4OwCEkXhlGR/xRrPwXQ=="}}],"evidence_files":[{"path":"package.json","sha256":"4516ba2b672e742658b040a522d3e9cc7e4c1346578edba6cad57cffca9fa0a2","tlsh":"a5f027004aa45b636ee836858d6a0286f7324c4b808c7c173beb451c47deba710bf15d"},{"path":"postinstall.js","sha256":"e5c7efaa25bd6fc20c40fe6e39a40957043022e78b5ec6d9ad2b9e49a3ef75c8","tlsh":"e241a755829891340fe122c9b852c8165d7bd49633e799f0774d15226fc92bc03b2fdf"}]},"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/wp-codebox-workspace/MAL-2026-6458.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}