VDB
EN

MAL-2026-5745

Malicious code in oa-crm-webapi (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (00cdaf89f7ae5fd12400ea55acd4849e8e5095dfc51188d3339ecdfa5dc0f2a1) oa-crm-webapi@9.9.99 is a dependency-confusion payload squatting an internal-sounding package name. package.json declares a postinstall hook (`node beacon.js`) which fires automatically on `npm install`. beacon.js reads `os.hostname()` and transmits it to the attacker-controlled Burp Collaborator host `yfhjhookbia8zov0q5hh772xroxfl69v.oastify.com` via two channels: a DNS lookup of `<nonce>.<hostname>.<collaborator-host>` (out-of-band DNS exfil) and an HTTPS POST to the same host with the hostname in the body. The 9.9.99 version + generic 'internal placeholder' description is the canonical shape used to hijack private package names by overriding the legitimate internal registry resolution. A successful install both proves code execution on the installer and leaks the internal hostname to an external attacker.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / oa-crm-webapi

No fixed version published yet for oa-crm-webapi (npm). Pin to a known-safe version or switch to an alternative.

참고