MAL-2026-11134
Malicious code in color-convert-helper (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (9ede9e30312b6e32aeb2a3ed39042fed67db7f1cee50591f906a228f61673ef9) The package's postinstall.js runs automatically on npm install and executes a shell pipeline that collects host identity (hostname, whoami, id, sudo -l, uname), CI/GitHub Actions environment variables, network interface information, running processes, and environment variables filtered by KEY/TOKEN/SECRET/CREDENTIAL/NPM/AZURE/GCP/CLOUD, then queries cloud instance-metadata endpoints (AWS/Aliyun/GCP/Tencent at 169.254.169.254) to fetch IAM security credentials. The collected data is base64-encoded and curled to the hardcoded attacker-controlled OAST domain pzs5w7ntzhsnepwk564lyfdci3oucl0a.oastify.com. The script also performs DNS and HTTP probes against the internal hostname tst.woa.com and issues an SSRF forwarder request, reporting resolvability back to the same OAST domain. The advertised purpose of the package is color conversion; the actual behavior is credential and cloud-IAM harvesting plus internal-perimeter reconnaissance from every install host.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for color-convert-helper (npm). Pin to a known-safe version or switch to an alternative.