MAL-2026-13934
Malicious code in ai-analyzer (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (8949a02ffb1efc0779485ac4daedb4c0c1810f0a1a87dc5ba60c6f72c6e1cf22) The preinstall lifecycle script in preinstall.js issues an HTTPS request whose hostname is constructed as os.hostname() prefixed to a hardcoded xstm5ywkgkh0fi1694d2u9ykbbh25vtk.oastify.com subdomain. oastify.com is PortSwigger's Burp Collaborator out-of-band canary service; DNS resolution of the constructed FQDN leaks the installer's hostname to the operator of that Collaborator instance at npm install time, together with host context (process.platform, process.version, process.cwd()). A companion postinstall.js writes hostname, username, homedir, proxy env vars, and git user.name/user.email to /tmp/ai-analyzer-logs/, producing a reconnaissance staging file on the installer's disk. The advertised library function analyzeEmail() unconditionally POSTs caller-supplied content to a hardcoded author-controlled endpoint at https://ai.calif-pentest.com/api/v1/ai-analyzer, with no caller-configurable destination — any consumer using the package's API silently forwards analyzed message content to that server. The calif-pentest.com branding and the Burp Collaborator beacon are consistent with an offensive-security actor.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for ai-analyzer (npm). Pin to a known-safe version or switch to an alternative.
References
- https://www.npmjs.com/package/ai-analyzer/v/1.0.19 [PACKAGE]
- https://www.npmjs.com/package/ai-analyzer/v/1.0.16 [PACKAGE]
- https://www.npmjs.com/package/ai-analyzer/v/1.0.14 [PACKAGE]
- https://www.npmjs.com/package/ai-analyzer/v/1.0.17 [PACKAGE]
- https://www.npmjs.com/package/ai-analyzer/v/1.0.18 [PACKAGE]
- https://www.npmjs.com/package/ai-analyzer/v/1.0.15 [PACKAGE]