{"id":"MAL-2026-6910","summary":"Malicious code in zluri-ad-connector (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (1b7a807f066f0255f7480ebd7d445043282260b464b0ef54a32a2d022c93bbf7)\nThe package declares a preinstall hook (`node index.js`) that runs automatically on `npm install`. index.js requires `os`, `dns`, `https`, `querystring`, and the local `package.json`, then harvests values from `process.env` matching a large sensitive-token allowlist (npm, GitHub, AWS, CI tokens, and generic `secret`/`token`/`password`/`api_key` names) along with `os.hostname()`, `os.userInfo()`, `os.platform()`, homedir, PATH, DNS server list, and package metadata. The collected bundle is POSTed over HTTPS to `y543452sgo96xsasfdr72ms4rvxmld92.oastify.com`, a Burp Collaborator subdomain used as an attacker-controlled exfiltration sink. The package name `zluri-ad-connector` combined with the canonical dependency-confusion version `9.9.9` indicates an intentional attempt to shadow a private Zluri internal package name so that CI resolvers pull this public malicious package.\n\n## Source: ossf-package-analysis (04e770be48b9eacfda9794e0b5865d9fb1a0232dfa90b97bfc05c75cb92dc8fe)\nThe OpenSSF Package Analysis project identified 'zluri-ad-connector' @ 9.9.9 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n","modified":"2026-07-08T15:31:46.001593773Z","published":"2026-07-07T06:25:49Z","database_specific":{"malicious-packages-origins":[{"versions":["9.9.9"],"source":"ossf-package-analysis","sha256":"04e770be48b9eacfda9794e0b5865d9fb1a0232dfa90b97bfc05c75cb92dc8fe","import_time":"2026-07-07T07:47:30.24702735Z","modified_time":"2026-07-07T06:25:49Z"},{"sha256":"1b7a807f066f0255f7480ebd7d445043282260b464b0ef54a32a2d022c93bbf7","import_time":"2026-07-08T15:19:05.435826168Z","id":"IN-MAL-2026-008062","modified_time":"2026-07-08T14:33:12Z","versions":["9.9.9"],"source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/zluri-ad-connector/v/9.9.9"}],"affected":[{"package":{"name":"zluri-ad-connector","ecosystem":"npm","purl":"pkg:npm/zluri-ad-connector"},"versions":["9.9.9"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/zluri-ad-connector/MAL-2026-6910.json","indicators":{"package_integrity":[{"filename":"zluri-ad-connector-9.9.9.tgz","hashes":{"sha512_sri":"sha512-M2WYzwRGHAgXJ4b4S1Otwt8q9GttpLcaIA/sjL3tIlK1r/px7szzfoOT2MZm1BGenY74mx+DrWh5x3lXB5NmsQ==","sha1":"c295986cddf95a26e5fe8329b3564a4c8a541ca7"}}],"evidence_files":[{"tlsh":"e84165ccd1a12a310ce60ac0685a500557aad3273a09b9d87aac43d45fcd9be12736e7","path":"index.js","sha256":"e2dfd19533d9f6f4d6fc7418770eef772df697a86d6edc3d0b59f51eccacd8fc"},{"tlsh":"2ae0d820ea716d2316d70355482660856261dfe70e583d0d378b153c8fae2b7aafa29f","path":"package.json","sha256":"b2b75d8d87182c37970229a57a743af44553b4f0534ec3f1d512d7d98f2c941f"}]},"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}]}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}