MAL-2026-13965
Malicious code in nc-verify-127942 (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (3ea69188e179cd73aa9f200d63e8faceb5d3aae622a8fe2d86bf7ae761b5f1e0) nc-verify-127942 declares a postinstall lifecycle hook ("postinstall": "node install-cb.js") that runs automatically on npm install. The install-cb.js script issues an HTTPS request and a DNS lookup to a Burp Collaborator subdomain under oastify.com (nc-verify-127942.owoemjgpf2c4qxqet92hexzvym4dsq6skvoa2cr.oastify.com), which confirms code execution on the installer's host and leaks install-side network identifiers (source IP, resolver) to an operator-controlled out-of-band endpoint. The package's own metadata labels it as a proof-of-concept for RCE verification; installing it in a normal developer or CI environment fires the beacon without any user interaction.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for nc-verify-127942 (npm). Pin to a known-safe version or switch to an alternative.