MAL-2026-13882
Malicious code in verify-cli (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (081d3a8717b3f05f688cdde25d2b0de315dd9b1f400382e0db00d53f8ca82d6b) package.json declares `preinstall: node index.js`, which runs automatically on `npm install`. index.js shells out via child_process and curl to POST the installer's `whoami`, `hostname`, and `id` output along with base64-encoded contents of `/etc/passwd`, `/etc/hosts`, and (if readable) `/etc/shadow` to a hardcoded out-of-band interactsh/OAST endpoint at `5f8a1ed70fb7761d678agw9bucryyyyyb.oast.site`. Package metadata shows an implausible version (99.0.0), placeholder description ("Nodejs SDK for Redacted"), and a nonexistent dependency, consistent with a dependency-confusion / typosquat beacon rather than a legitimate SDK.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for verify-cli (npm). Pin to a known-safe version or switch to an alternative.