MAL-2026-10081

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/webrix-docs1/MAL-2026-10081.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-10081
Published
2026-07-09T15:45:53Z
Modified
2026-07-09T16:32:05.703993149Z
Summary
Malicious code in webrix-docs1 (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (20cdefe1415c5b5245f36b10ea0de9033433b479768c2cc785ad2742b9433fce)

The package declares a preinstall hook (node index.js) that fires automatically on npm install. The script requires child_process, os, https, and http, collects hostname, platform, arch, username/uid/gid, shell, home directory, CPU/memory stats, cwd, and the output of whoami/id, then POSTs the JSON payload to a hardcoded Burp Collaborator (oastify.com) subdomain at https://c7kfuaf25guwigaz6r03kxet0k6bu3is.oastify.com/detox56. The package has an empty description and empty author, presents no advertised functionality, and its name mimics the webrix project — consistent with dependency-confusion/typosquat recon. Installing the package directly leaks installer host and user identifiers to an attacker-controlled OAST endpoint.

Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2026-07-09T16:20:52.286618381Z",
            "sha256": "20cdefe1415c5b5245f36b10ea0de9033433b479768c2cc785ad2742b9433fce",
            "versions": [
                "10.2.11"
            ],
            "id": "IN-MAL-2026-009221",
            "modified_time": "2026-07-09T15:45:53Z",
            "source": "amazon-inspector"
        }
    ]
}
References
Credits

Affected packages

npm / webrix-docs1

Package

Affected ranges

Affected versions

10.*
10.2.11

Database specific

cwes
[
    {
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature."
    }
]
indicators
{
    "package_integrity": [
        {
            "filename": "webrix-docs1-10.2.11.tgz",
            "hashes": {
                "sha512_sri": "sha512-IhE1D8dgie8/RECERBcZYEwmmrvn43wo6MJ6jcq7QhQt/ROEYfWKqQyhq12d8NHMQ9IwEi+pSp3T1Ya+1sI2Nw==",
                "sha1": "eb0ea97db60c29957ce9db08f8132fe85b63daba"
            }
        }
    ],
    "evidence_files": [
        {
            "sha256": "47f1b70eb518ccb31df256490ddd800165fe3f0d1657e4e6c0e7e7ec22e9adb2",
            "path": "index.js",
            "tlsh": "bf5140c515f65a251ba7b8494a4f9012a327e0033509ee55bfcc8340af9937c97f0bf6"
        },
        {
            "sha256": "df189ce49e0879e02a7fe10e2538abddbcc3bb6379229ebdf6c82071166b32ea",
            "path": "package.json",
            "tlsh": "ccd0a7304e21553365c106620c2ba59772619f2f04157c0863df1c2c82de67798ff34e"
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/webrix-docs1/MAL-2026-10081.json"