-= Per source details. Do not edit below this line.=-
On npm install, postinstall.js automatically runs and gathers installer-identifying data (os.hostname(), os.userInfo(), os.platform(), cwd, Node version, timestamp), then sends it as query-string parameters via plain-HTTP GET to a Burp Collaborator subdomain at aq4v2egelzh9n07h3l9d2b5mvd14pvdk.oastify.com/adjust-dep-confusion. The package.json description self-identifies as a dependency-confusion proof-of-concept ("PoC - Dependency Confusion - Bug Bounty by ha4x0r"), and the package name targets an internal/private package name. Any organization whose build misresolves to this public package leaks host, user, and environment identifiers to the third-party Collaborator endpoint on install. PoC/bug-bounty framing does not change the installer-side impact: the beacon fires on every install.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-009360",
"import_time": "2026-07-09T17:19:28.960426558Z",
"modified_time": "2026-07-09T17:00:59Z",
"sha256": "21445a74cc1c4d33c89f1a7d8c357c79d5adb11cda135c813676b23c875418e9",
"source": "amazon-inspector",
"versions": [
"3.0.0"
]
},
{
"id": "RLMA-2026-05522",
"import_time": "2026-07-20T13:14:45.210269957Z",
"modified_time": "2026-07-20T10:38:10Z",
"sha256": "8a0866f3469405ec2768c987abf110354927c943f2d2a5303834ff7e6deccf5f",
"source": "reversing-labs",
"versions": [
"3.0.0"
]
},
{
"id": "RLUA-2026-06165",
"import_time": "2026-09-01T11:18:01.09108056Z",
"modified_time": "2026-08-24T16:45:27Z",
"sha256": "24dbc577c559551551b0c3789a0372f81b9f34699527ff29265da7912ff49c70",
"source": "reversing-labs"
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "postinstall.js",
"sha256": "dadaad150a1789aec709a78a41507ff0d88d2ab999dc6622e3574d9ea5f34b49",
"tlsh": "e7f0acf0a2a5ebb81974a7d0a26a080793bbd1057d5bbcd1daa940986b5c2a402b05f4"
},
{
"path": "package.json",
"sha256": "5c3b9e3047d939f4160b1a93994530150054fdc54004292ba8fa3e5287d5d6a2",
"tlsh": "dfd097240e62aa3378c50b860833500f27324e0b020c7c8c13e724a8229e3b74abf31f"
}
],
"package_integrity": [
{
"filename": "conversionvaluemanager-3.0.0.tgz",
"hashes": {
"sha1": "dd96a7ab22110ff8458ff5a10bfcca9e6eaead42",
"sha512_sri": "sha512-v5eYv9MQ27vNNjFWjRJoadgOlE9Y9EPY7QVPzwaJ+5HfF9wovie2dWlmDCivObNOS0kDYFiiPSb4fsoayPz0JA=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/conversionvaluemanager/MAL-2026-10084.json"