MAL-2026-16153
Malicious code in web-main (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (61680a5d53758bc9eb99b1cd2566e6e19139d09fee10a0096a5e72bb0953a5b2) package.json declares `preinstall: node index.js`, causing index.js to execute automatically on `npm install`. The script collects os.hostname(), os.userInfo() (username/uid/gid/shell), platform, arch, homedir, and the stdout of `whoami`, `id`, and `pwd` via child_process.exec, then POSTs the aggregated JSON to a hardcoded endpoint at https://smi54v4uvb9q7ve5t6fnyro16scj0co1.oastify.com/system-info (a Burp Collaborator out-of-band host). No legitimate functionality is present; the package's sole effect on install is host reconnaissance and exfiltration to an attacker-controlled OOB collector.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for web-main (npm). Pin to a known-safe version or switch to an alternative.