-= Per source details. Do not edit below this line.=-
Package published to the public @iana-rzms scope as a dependency-confusion squat targeting an internal ICANN namespace. The preinstall lifecycle script runs automatically on npm install and collects the installer's hostname, OS username, and current working directory, base64-encodes them, and transmits them via HTTPS (port 443), HTTP (port 80), and DNS lookup to the hardcoded external host k4pzh6vg78iub3vxqhmml2q8wz2qqge5.oastify.com (a Burp Collaborator subdomain). The self-described 'authorized PoC' framing in the README does not change installer-side impact: any build that resolves @iana-rzms/bff-sdk from the public registry executes attacker/researcher-controlled code at install time and leaks host identity to a non-first-party collector.
{
"malicious-packages-origins": [
{
"import_time": "2026-07-13T07:40:09.767603398Z",
"sha256": "b7adbad0c719aec3345c5aa16b3435e8621f4a81b5a0e0cf0e0d979509e5d21f",
"modified_time": "2026-07-13T05:58:14Z",
"versions": [
"1.0.0"
],
"source": "amazon-inspector",
"id": "IN-MAL-2026-009802"
}
]
}[
{
"cweId": "CWE-506",
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature."
}
]
{
"package_integrity": [
{
"filename": "bff-sdk-1.0.0.tgz",
"hashes": {
"sha1": "8b3adfce8f176427bd4e4874da1982de694ba820",
"sha512_sri": "sha512-6Diifi8G8QWzPJ7z62zPWTrCX2jLRHIHIhWz0YPWajDrMsqsT/J+89fJ/Gf4sQAR0llVK77vpjFXnalUPNK4hQ=="
}
}
],
"evidence_files": [
{
"tlsh": "bc51c5bf44f0511005f371e1cb6f7268936bf0028f96ca88b4ade218af29a280122df5",
"sha256": "66c65ba997c6f137c332031715fd5ac99bca238539300d3c3561856d376a46d3",
"path": "preinstall.js"
},
{
"tlsh": "d6f0ac350412a93324d2bbe20d6f691266b758fa1028390d56db002cc69eb6b47bf63f",
"sha256": "c37932a6e3e555dad0fa3afbb20d4389d1ae83e0dac55586eef25a65dc2a2106",
"path": "package.json"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@iana-rzms/bff-sdk/MAL-2026-10403.json"