{"id":"MAL-2026-6990","summary":"Malicious code in ai-gen-ai-opt-in (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (a34dae027378ca986d5e99aa7c9ffc5efe590e4697e1255970ce713f6d309e74)\nai-gen-ai-opt-in@99.0.0 declares a postinstall hook (postinstall.js) that runs automatically on npm install. The script collects the installer's hostname (os.hostname()), OS username (os.userInfo().username), and public IP/geo/ISP data (fetched from ip-api.com over HTTPS), then encodes those values and issues a DNS lookup for a subdomain of an attacker-controlled Burp Collaborator-style callback host (p1r2d74iwjk057raam6myf7e258wzkt8i.oastify.com). This is a covert out-of-band DNS exfiltration channel that leaks installer identity and location data to a third party on every install, with no legitimate documented purpose.\n","modified":"2026-07-08T17:16:44.908121823Z","published":"2026-07-08T16:21:20Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-07-08T16:21:20Z","sha256":"a34dae027378ca986d5e99aa7c9ffc5efe590e4697e1255970ce713f6d309e74","source":"amazon-inspector","versions":["99.0.0"],"id":"IN-MAL-2026-008077","import_time":"2026-07-08T17:01:28.747348442Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/ai-gen-ai-opt-in/v/99.0.0"}],"affected":[{"package":{"name":"ai-gen-ai-opt-in","ecosystem":"npm","purl":"pkg:npm/ai-gen-ai-opt-in"},"versions":["99.0.0"],"database_specific":{"indicators":{"package_integrity":[{"filename":"ai-gen-ai-opt-in-99.0.0.tgz","hashes":{"sha1":"0210e66192a57ba9b6814280d633750063c0676c","sha512_sri":"sha512-S9Q4iI6b3os/9QutMknL68k2Crc4hJPpRdsmpASPndt2gsXzzzeLYilkPARPbSvWYO3oVkYrsLtUonXYlUKwnA=="}}],"evidence_files":[{"path":"postinstall.js","sha256":"4adbfd26be37cb08cc308e2aa23d2319462ad80247ffb54613fd33b30450eb68","tlsh":"5921d0ae7672512409f21bc7620fd916786bf13325c2f8b079ac5380ef8157841b15fe"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/ai-gen-ai-opt-in/MAL-2026-6990.json","cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}]}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}