VDB
KO

MAL-2026-13952

Malicious code in global-intel (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (5449036ad6a1bf0ee192023ddb23ea7afefe53da7133ab91f4ffbc6d3253f5dc) package.json declares a preinstall hook that runs index.js on `npm install`. index.js collects host identity and OS files from the installer — os.hostname(), os.userInfo(), homedir, DNS server configuration, /etc/passwd, /etc/hosts, and package metadata — and HTTPS POSTs the payload to the hardcoded out-of-band host `0gh240ybp2rb80iyzrg4w2o3tuzlncb1.oastify.com` (Burp Collaborator). The exfiltration fires automatically as a lifecycle side effect of installation with no user interaction.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / global-intel

No fixed version published yet for global-intel (npm). Pin to a known-safe version or switch to an alternative.

References