VDB
KO

MAL-2026-13481

Malicious code in cdf-tag-commander-helper (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (945179057c5bd93b985c3c532baa35379ce9dd9603e26d17e63201beb25868ae) The preinstall lifecycle script in cdf-tag-commander-helper@3.6.2 runs automatically on `npm install`. It executes `whoami` and `hostname`, retrieves the machine's public IP via ifconfig.me, and issues a plain-HTTP GET to a hardcoded Interactsh-style out-of-band callback subdomain (kwphewvexhjbtfduscqybx6q7c862eh0g.oast.fun), passing the three values as query parameters. The README states that the package makes no network requests, which contradicts the shipped code. The behavior is a reconnaissance beacon consistent with dependency-confusion targeting: on install, an attacker learns which internal build hosts and user accounts have resolved this package name.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / cdf-tag-commander-helper

No fixed version published yet for cdf-tag-commander-helper (npm). Pin to a known-safe version or switch to an alternative.

References