MAL-2026-13755
Malicious code in ghazaly (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (d2054792481618ddf941c251fc0793ec8c1b85fe14107567b5c29cac9330d5be) package.json declares a postinstall hook that executes index.js on npm install. index.js requires os, https, and child_process, runs `whoami` via execSync, and reads os.hostname(), process.cwd(), and non-internal IPv4 addresses from os.networkInterfaces(). The collected host and identity data is sent as query-string parameters via https.get to a hardcoded Burp Collaborator subdomain (xghhv5sajm33m7krgi4n8my0mrsig84x.oastify.com). Package metadata is consistent with a dependency-confusion lure: version 99.9.0, empty author/description/keywords, and a nonsense dependency name `dependencyfsdsfdsfg` pinned to ^99.9.0.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for ghazaly (npm). Pin to a known-safe version or switch to an alternative.