{"id":"MAL-2026-6485","summary":"Malicious code in starship-timeline (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (8a4e552337fa70064e0a04644ee5a64378809a85b281eda24707bc9a6eba473f)\nstarship-timeline@1.0.1 ships no real functionality. Its package.json declares a preinstall hook (`\"preinstall\": \"node index.js\"`) that runs automatically on `npm install`. index.js collects hostname, username, home directory, DNS servers, package metadata, and the contents of `/etc/passwd` and `/etc/hosts`, then POSTs the bundle over HTTPS to a hardcoded Burp Collaborator (`*.oastify.com`) subdomain (`5tziqozihbss8jg955ez91bycpij69uy.oastify.com`). The package has empty author and description fields, a single published version, and no other code paths — the exfiltration beacon is its only purpose, matching the standard dependency-confusion / OOB-beacon pattern. Whether deployed as research or as a live attack, installing the package leaks identifying host data and sensitive system files to an attacker-controlled out-of-band endpoint.\n","modified":"2026-06-25T23:16:23.824554728Z","published":"2026-06-25T22:13:52Z","database_specific":{"malicious-packages-origins":[{"versions":["1.0.1"],"id":"IN-MAL-2026-007539","import_time":"2026-06-25T23:00:33.037135162Z","modified_time":"2026-06-25T22:13:52Z","sha256":"8a4e552337fa70064e0a04644ee5a64378809a85b281eda24707bc9a6eba473f","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/starship-timeline/v/1.0.1"}],"affected":[{"package":{"name":"starship-timeline","ecosystem":"npm","purl":"pkg:npm/starship-timeline"},"versions":["1.0.1"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"path":"index.js","sha256":"7177b614bdcc11258526f8156101940a0442fda8bb2414d3bc211179580a7d92","tlsh":"d7411199a2c917330dd210c06a0c70812359fa777159e99076cf42d6af869f8b7326f3"},{"path":"package.json","sha256":"dcf24e4997f91a81385a4f9156765d9c4e83e7a847f0527b77c169689c04ab6d","tlsh":"f4d0a7345d62653365c506660c2ba48773718f2f14057c09a7cf582c91de67798ff31d"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/starship-timeline/MAL-2026-6485.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}