VDB
KO

MAL-2026-12482

Malicious code in tool-registry-scripts (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (b635b8b6d257c079a0d0a9c06e37910b67f2e75d1e71dced264043624951ce06) package.json declares a preinstall hook that runs index.js on `npm install`. index.js collects host identifiers (os.hostname(), os.userInfo(), homedir, DNS servers, cwd, package.json contents) and reads /etc/passwd and /etc/hosts, then POSTs the resulting JSON over HTTPS to the hardcoded out-of-band collaborator subdomain lsh5x8dwumsekllw37kacgaqxh3cr2fr.oastify.com. The destination is a Burp Collaborator OOB endpoint unrelated to any documented package purpose, and execution is automatic at install time.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / tool-registry-scripts

No fixed version published yet for tool-registry-scripts (npm). Pin to a known-safe version or switch to an alternative.

References