VDB
KO

MAL-2026-13882

Malicious code in verify-cli (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (081d3a8717b3f05f688cdde25d2b0de315dd9b1f400382e0db00d53f8ca82d6b) package.json declares `preinstall: node index.js`, which runs automatically on `npm install`. index.js shells out via child_process and curl to POST the installer's `whoami`, `hostname`, and `id` output along with base64-encoded contents of `/etc/passwd`, `/etc/hosts`, and (if readable) `/etc/shadow` to a hardcoded out-of-band interactsh/OAST endpoint at `5f8a1ed70fb7761d678agw9bucryyyyyb.oast.site`. Package metadata shows an implausible version (99.0.0), placeholder description ("Nodejs SDK for Redacted"), and a nonexistent dependency, consistent with a dependency-confusion / typosquat beacon rather than a legitimate SDK.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / verify-cli

No fixed version published yet for verify-cli (npm). Pin to a known-safe version or switch to an alternative.

References