VDB
KO

MAL-2026-11137

Malicious code in jobber-app-template-react (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (844a2ac73b588b6c0c7c370dd647685768992ff3e6b5ef492e6fc6dc6be240ce) The package's preinstall hook runs index.js which fires automatically on `npm install`. The script collects host reconnaissance (os.hostname(), os.userInfo().username, home directory, DNS servers, __dirname) and reads the contents of /etc/passwd and /etc/hosts from the installer's machine, then HTTPS-POSTs a JSON payload to the hardcoded Burp Collaborator subdomain 5tzh3l2e1cetr1chf6osh4tg57b0zqnf.oastify.com. The behavior is unrelated to the package's advertised purpose as a React app template and is characteristic of a dependency-confusion exfiltration payload.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / jobber-app-template-react

No fixed version published yet for jobber-app-template-react (npm). Pin to a known-safe version or switch to an alternative.

References