{"id":"MAL-2026-6479","summary":"Malicious code in @salem_jalal/osc-components (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (cb26651411f61b6420c6291f7b3a7a4869bb670f1d4c75ddfc37481c50f3aae7)\nThe package's postinstall hook (install.js, wired via package.json scripts.postinstall) runs on every `npm install` and transmits installer host identifiers — hostname, OS platform/arch, username, current working directory, Node version, npm registry env, and DNS server list — to http://dm-tech.ly:8001/poc-osc/callback over plain HTTP as a URL-encoded query parameter. The main module (index.js) contains an IIFE that, when loaded in a browser context (e.g., bundled into a downstream web app), harvests document.cookie, all localStorage entries, the current URL, and userAgent, and ships them to http://dm-tech.ly:8001/poc-osc/exfil with `credentials:'include'`. Although published under the personal scope @salem_jalal, the payload self-identifies internally as `@dx-ui/osc-components` at the same version `1981.17.7`, indicating a dependency-confusion / namespace-impersonation attack against the @dx-ui scope. Console and path strings labeled `[PoC]` / `poc-osc` are cover framing; the code runs unconditionally on real installers.\n","modified":"2026-06-25T23:16:24.451922982Z","published":"2026-06-25T22:23:33Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-06-25T22:23:33Z","sha256":"cb26651411f61b6420c6291f7b3a7a4869bb670f1d4c75ddfc37481c50f3aae7","source":"amazon-inspector","versions":["1981.17.7"],"id":"IN-MAL-2026-007550","import_time":"2026-06-25T23:00:33.858602798Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@salem_jalal/osc-components/v/1981.17.7"}],"affected":[{"package":{"name":"@salem_jalal/osc-components","ecosystem":"npm","purl":"pkg:npm/%40salem_jalal%2Fosc-components"},"versions":["1981.17.7"],"database_specific":{"indicators":{"evidence_files":[{"tlsh":"c901bde956dcc9653af75680b6b6500756baf200360674e0faea43d2138d86486b23f0","path":"install.js","sha256":"1cde3aebf2c32f7d5e402719cd8a22fdda666fb04fbc65fff5ae481a27e02d94"},{"sha256":"4846405a37bee9f21ae4fd6247f70a23c8b332d42a6264fe11e37131ab0905bc","tlsh":"440123a935a42555105720a926b3300ab03af463bd5d62f4b1ca0a413f4d32f83a61cd","path":"index.js"}],"package_integrity":[{"filename":"osc-components-1981.17.7.tgz","hashes":{"sha512_sri":"sha512-cPZ26monDGv9PZQBGer2AQPhFcXcprcwknI3VCscwuPNWf5sidZ6c8PCDBCvi+8vT9jGSeFeZzZ3O6XMBt6Png==","sha1":"fb3d3d0152e68717e139f3b22ebe4f20666bd33b"}}]},"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@salem_jalal/osc-components/MAL-2026-6479.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}