VDB
Sign up

MAL-2026-16479

Malicious code in simplenewnpmpackage (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (76315a0ce965c3a1f5b6342caa9d9ce8db4b341b641b2dbb696ebd52bd6149ec) On require/import, index.js issues an HTTPS GET to a hardcoded interactsh OAST subdomain (dapnhid534ch06s9vpm0mbg1httu5gytc.oast.fun) with the installer's os.platform() and os.hostname() as query parameters. The package ships no other functionality; its main module exists solely to fire this out-of-band beacon on load. oast.fun is a public out-of-band interaction collector used to receive callbacks from targets, and the hardcoded subdomain is bound to a specific listener controlled by whoever published the package. This is the canonical dependency-confusion / namesquat probe pattern, in which a package is published to catch internal-name mis-resolutions and report back the host that installed it.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/simplenewnpmpackage

No fixed version published yet for simplenewnpmpackage (npm). Pin to a known-safe version or switch to an alternative.

References