MAL-2026-12419
Malicious code in pp-react-worldready-v5 (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (435cbd5d4dffc9d7e61222051c82a376bf6dd5a484760803953484ea0fa21b39) The tarball contains only package.json and vishu.js; the declared main (index.js) is absent, so the package has no library functionality. package.json.scripts.preinstall runs `node vishu.js`, which fires automatically on `npm install`. vishu.js resolves the installer's public IP via api.ipify.org, reads os.hostname() and GitHub Actions environment variables (CI, GITHUB_ACTIONS, GITHUB_WORKFLOW, GITHUB_RUN_ID, GITHUB_RUN_NUMBER, GITHUB_RUN_ATTEMPT), and sends them as query parameters in an HTTPS GET to https://webhook.site/1b840cbf-f1a4-4d79-bf11-f1ef62949110. It also issues a DNS lookup for `ping-<hostname>.your-collab-domain.oastify.com`, encoding the installer's hostname as a subdomain of a Burp Collaborator (OAST) host for out-of-band exfiltration. The package name resembles a typosquat pattern consistent with dependency-confusion reconnaissance.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for pp-react-worldready-v5 (npm). Pin to a known-safe version or switch to an alternative.