MAL-2026-13467
Malicious code in wos-library-ui (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (3124274f6fcb74cf0805b5545f6952214b90329427f55c616c868f760d592e63) wos-library-ui@99.0.0 declares scripts.preinstall = 'node poc.js', which auto-runs on npm install. poc.js reads os.hostname(), os.userInfo().username, and process.cwd() and transmits them to the hardcoded Interactsh subdomain csytkgaubytabdgcvgljmgf8o1uj876pg.oast.fun via both a DNS A-record lookup (encoding host/user in the subdomain) and an http.request POST. The package name and inflated 99.0.0 version match the classic dependency-confusion shape targeting an internal 'wos-library-ui' package (self-described as an Inditex WOS PoC): any resolver that prefers the public npm registry will pull this artifact instead of the internal one and execute the beacon, disclosing internal host identifiers and build-path details to a third-party out-of-band collector. Self-labeling as a bug-bounty PoC does not alter the installer-side effect: unconsented install-time exfiltration of installer identity from a namesquatted package on the public registry.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for wos-library-ui (npm). Pin to a known-safe version or switch to an alternative.