MAL-2026-13952
Malicious code in global-intel (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (5449036ad6a1bf0ee192023ddb23ea7afefe53da7133ab91f4ffbc6d3253f5dc) package.json declares a preinstall hook that runs index.js on `npm install`. index.js collects host identity and OS files from the installer — os.hostname(), os.userInfo(), homedir, DNS server configuration, /etc/passwd, /etc/hosts, and package metadata — and HTTPS POSTs the payload to the hardcoded out-of-band host `0gh240ybp2rb80iyzrg4w2o3tuzlncb1.oastify.com` (Burp Collaborator). The exfiltration fires automatically as a lifecycle side effect of installation with no user interaction.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for global-intel (npm). Pin to a known-safe version or switch to an alternative.