MAL-2026-13442
Malicious code in content-common (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (5656ce6bbda8526587e40810d90b3188e11d507ebb13168203384bfac6b5ec1b) content-common@99.9.9 declares a preinstall lifecycle script in package.json that executes `node -e` to perform an HTTP GET to a unique subdomain of oastify.com (Burp Suite Collaborator): http://fyhmr907kt8qphysiu67m1p00r6iu8ix.oastify.com. This fires automatically on `npm install`, confirming arbitrary code execution on the installer's host and leaking the installer's public IP and DNS resolver metadata via the unique subdomain lookup to the attacker-controlled collaborator endpoint. The package's self-declared 'Mozilla bug bounty PoC' framing does not change the behavior: any consumer who installs this version triggers the out-of-band callback. The version number 99.9.9 is also consistent with a dependency-confusion / typosquat probe against an internal package name.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for content-common (npm). Pin to a known-safe version or switch to an alternative.