MAL-2026-16479
Malicious code in simplenewnpmpackage (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (76315a0ce965c3a1f5b6342caa9d9ce8db4b341b641b2dbb696ebd52bd6149ec) On require/import, index.js issues an HTTPS GET to a hardcoded interactsh OAST subdomain (dapnhid534ch06s9vpm0mbg1httu5gytc.oast.fun) with the installer's os.platform() and os.hostname() as query parameters. The package ships no other functionality; its main module exists solely to fire this out-of-band beacon on load. oast.fun is a public out-of-band interaction collector used to receive callbacks from targets, and the hardcoded subdomain is bound to a specific listener controlled by whoever published the package. This is the canonical dependency-confusion / namesquat probe pattern, in which a package is published to catch internal-name mis-resolutions and report back the host that installed it.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for simplenewnpmpackage (npm). Pin to a known-safe version or switch to an alternative.