{"id":"MAL-2026-919","summary":"Malicious code in mds-webcomponents (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (4b33015300fa18b6b3d2c2f1c0af0e77cbd9fa96c7af7befbe61a5422165824e)\npackage.json declares `preinstall: node index.js`, which runs automatically on every `npm install`. index.js collects os.homedir(), os.hostname(), os.userInfo().username, dns.getServers(), the package name, __dirname, and the full package.json contents, then HTTPS POSTs them as a querystring `msg=...` parameter to `2mpf1804g4gnfnvuqqx3om0cw32vqlea.oastify.com` — a Burp Collaborator (oastify.com) subdomain used as an out-of-band recon/exfiltration channel. The package provides no legitimate functionality; its only on-install effect is to leak installer host identity and project metadata to an attacker-controlled endpoint. This is the canonical dependency-confusion / red-team recon beacon shape.\n\n## Source: ossf-package-analysis (d35cd4fc7e553141b386ee1a6a68e45c41d5ae73d8e013beafd90f6dfc4b1afd)\nThe OpenSSF Package Analysis project identified 'mds-webcomponents' @ 1.0.0 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n","modified":"2026-06-10T19:31:29.091879672Z","published":"2026-02-16T15:20:34Z","database_specific":{"malicious-packages-origins":[{"versions":["1.0.0"],"source":"ossf-package-analysis","sha256":"d35cd4fc7e553141b386ee1a6a68e45c41d5ae73d8e013beafd90f6dfc4b1afd","import_time":"2026-02-16T15:47:33.56876671Z","modified_time":"2026-02-16T15:20:34Z"},{"versions":["1.0.0"],"source":"amazon-inspector","sha256":"7f6007f508051582581cb5f52ff3494c5da6bb9ad1b6725fa6801b5c1b8e0825","import_time":"2026-02-23T04:19:44.88544304Z","modified_time":"2026-02-23T03:51:30Z"},{"sha256":"4b33015300fa18b6b3d2c2f1c0af0e77cbd9fa96c7af7befbe61a5422165824e","import_time":"2026-06-10T19:23:48.94911186Z","id":"IN-MAL-2026-005297","modified_time":"2026-06-10T18:43:27Z","versions":["1.0.2"],"source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/mds-webcomponents/v/1.0.2"}],"affected":[{"package":{"name":"mds-webcomponents","ecosystem":"npm","purl":"pkg:npm/mds-webcomponents"},"versions":["1.0.0","1.0.2"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"evidence_files":[{"path":"index.js","sha256":"7f93708b58a0ea2cf08690a1a9619f2c16deb2221be984d1dd765bdad139000c","tlsh":"3711bde8c2922360097989d0b8bdd04c16fee734b10e49e895cd07d547c2af410b39e1"}],"package_integrity":[{"filename":"mds-webcomponents-1.0.2.tgz","hashes":{"sha1":"9a5c7acf67e271e3cd2ced2cbe92ad66e65cae6c","sha512_sri":"sha512-NZgzQXOUEB6o/JyOhNRnB3pYvD92GOn/s/l1aVcnYEckfmz1JQ8VANC+bPIJ5qOfObt7YA681LmGlq5HoY7Ftg=="}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/mds-webcomponents/MAL-2026-919.json"}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com","inspector-research@amazon.com"],"type":"FINDER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}