MAL-2026-13744
Malicious code in @dgn-src-click-to-pay-org/srcdcfreleasecert (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (6c203676b4cd54080189fef8d6740d09a1667f2ba0d939936ee46bd6dda4e15d) The package's postinstall hook (scripts/check-env.js) executes on npm install and POSTs the package name/version along with the host's platform, architecture, and Node.js version to a hardcoded bare-IP endpoint at http://16-171-38-148.sslip.io:8080/api/install over plain HTTP. The package is published at version 999.0.1 — a sentinel value chosen to outrank legitimate internal versions during resolution — under a scoped organization name evoking a payments vendor (Discover/SRC click-to-pay), while the module body contains only trivial PAN/Luhn helpers. This is the canonical dependency-confusion reconnaissance shape: the squatted scope resolves inside a target build system and the postinstall beacon reports back which internal environments were successfully hijacked, enabling attacker follow-up against those hosts.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for @dgn-src-click-to-pay-org/srcdcfreleasecert (npm). Pin to a known-safe version or switch to an alternative.