MAL-2026-12355
Malicious code in com.db.dbk.ui-forms (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (c74649b28994f970d4972ffb8708378b355186eb729bf2e4c45d6acd16346e5d) com.db.dbk.ui-forms@99.0.1 is a version-inflated package published to the public npm registry under a scope that resembles an internal namespace. Its package.json declares `preinstall: node index.js`, which runs automatically on `npm install`. index.js collects host identifiers (os.hostname(), os.platform(), os.userInfo(), homedir, network interfaces) and the output of shell commands (uname, id, whoami) via child_process, and enumerates process.env for keys matching /key|token|secret|pass|auth|cred|npm|ci|build|jenkins|github|gitlab|aws|azure/i. The collected payload is POSTed via https.request/http.request to the hardcoded interactsh callback host `ycwyyoimdcluajepubahl0tpb7943a2z4.oast.fun` at path `/dcf/<pkg>`, with a base64-chunked copy also emitted via DNS lookups to the same host. The package.json self-describes as a `dependency confusion proof of concept`; the installer-side behavior is exfiltration regardless of that framing.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for com.db.dbk.ui-forms (npm). Pin to a known-safe version or switch to an alternative.