MAL-2026-12791
Malicious code in gs-uitk-object-utils (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (662b350826118282a93e76c970ab25659d7bc3a52c58e1e16466e4c432d0d1e5) package.json declares scripts.install: `node index.js`, which requires `./lib/core`. lib/core.js reads the OS username, hostname, and current working-directory basename, assembles them with a hardcoded `goldman1` prefix into a subdomain of `oob.sl4x0.xyz`, and issues a `dns.resolve4` lookup against that name, causing the installer's host identifiers to be transmitted as a DNS query to the attacker-controlled authoritative server. The destination domain, prefix, and API names (`os`, `dns`, `userInfo`, `hostname`, `cwd`, `resolve4`) are stored as char-code arrays in lib/b02e30.js and lib/6ad264.js and decoded at runtime via String.fromCharCode, concealing the exfiltration path. The same code also fires on `require()` of the package. The package presents itself as an object-utility library, which does not match the observed install-time DNS beaconing.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for gs-uitk-object-utils (npm). Pin to a known-safe version or switch to an alternative.