-= Per source details. Do not edit below this line.=-
The package declares a preinstall hook (node index.js) that fires automatically on npm install. The script requires child_process, os, https, and http, collects hostname, platform, arch, username/uid/gid, shell, home directory, CPU/memory stats, cwd, and the output of whoami/id, then POSTs the JSON payload to a hardcoded Burp Collaborator (oastify.com) subdomain at https://c7kfuaf25guwigaz6r03kxet0k6bu3is.oastify.com/detox56. The package has an empty description and empty author, presents no advertised functionality, and its name mimics the webrix project — consistent with dependency-confusion/typosquat recon. Installing the package directly leaks installer host and user identifiers to an attacker-controlled OAST endpoint.
{
"malicious-packages-origins": [
{
"import_time": "2026-07-09T16:20:52.286618381Z",
"sha256": "20cdefe1415c5b5245f36b10ea0de9033433b479768c2cc785ad2742b9433fce",
"versions": [
"10.2.11"
],
"id": "IN-MAL-2026-009221",
"modified_time": "2026-07-09T15:45:53Z",
"source": "amazon-inspector"
}
]
}[
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
}
]
{
"package_integrity": [
{
"filename": "webrix-docs1-10.2.11.tgz",
"hashes": {
"sha512_sri": "sha512-IhE1D8dgie8/RECERBcZYEwmmrvn43wo6MJ6jcq7QhQt/ROEYfWKqQyhq12d8NHMQ9IwEi+pSp3T1Ya+1sI2Nw==",
"sha1": "eb0ea97db60c29957ce9db08f8132fe85b63daba"
}
}
],
"evidence_files": [
{
"sha256": "47f1b70eb518ccb31df256490ddd800165fe3f0d1657e4e6c0e7e7ec22e9adb2",
"path": "index.js",
"tlsh": "bf5140c515f65a251ba7b8494a4f9012a327e0033509ee55bfcc8340af9937c97f0bf6"
},
{
"sha256": "df189ce49e0879e02a7fe10e2538abddbcc3bb6379229ebdf6c82071166b32ea",
"path": "package.json",
"tlsh": "ccd0a7304e21553365c106620c2ba59772619f2f04157c0863df1c2c82de67798ff34e"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/webrix-docs1/MAL-2026-10081.json"