VDB
KO

MAL-2026-13744

Malicious code in @dgn-src-click-to-pay-org/srcdcfreleasecert (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (6c203676b4cd54080189fef8d6740d09a1667f2ba0d939936ee46bd6dda4e15d) The package's postinstall hook (scripts/check-env.js) executes on npm install and POSTs the package name/version along with the host's platform, architecture, and Node.js version to a hardcoded bare-IP endpoint at http://16-171-38-148.sslip.io:8080/api/install over plain HTTP. The package is published at version 999.0.1 — a sentinel value chosen to outrank legitimate internal versions during resolution — under a scoped organization name evoking a payments vendor (Discover/SRC click-to-pay), while the module body contains only trivial PAN/Luhn helpers. This is the canonical dependency-confusion reconnaissance shape: the squatted scope resolves inside a target build system and the postinstall beacon reports back which internal environments were successfully hijacked, enabling attacker follow-up against those hosts.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / @dgn-src-click-to-pay-org/srcdcfreleasecert

No fixed version published yet for @dgn-src-click-to-pay-org/srcdcfreleasecert (npm). Pin to a known-safe version or switch to an alternative.

References