MAL-2026-13481
Malicious code in cdf-tag-commander-helper (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (945179057c5bd93b985c3c532baa35379ce9dd9603e26d17e63201beb25868ae) The preinstall lifecycle script in cdf-tag-commander-helper@3.6.2 runs automatically on `npm install`. It executes `whoami` and `hostname`, retrieves the machine's public IP via ifconfig.me, and issues a plain-HTTP GET to a hardcoded Interactsh-style out-of-band callback subdomain (kwphewvexhjbtfduscqybx6q7c862eh0g.oast.fun), passing the three values as query parameters. The README states that the package makes no network requests, which contradicts the shipped code. The behavior is a reconnaissance beacon consistent with dependency-confusion targeting: on install, an attacker learns which internal build hosts and user accounts have resolved this package name.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for cdf-tag-commander-helper (npm). Pin to a known-safe version or switch to an alternative.