-= Per source details. Do not edit below this line.=-
clerk-next-fix-auth-protection@8.8.8 is a typosquat of Clerk/Next.js auth tooling that ships no functional code (declared main index.js is absent from the tarball). Both preinstall and postinstall lifecycle hooks in package.json run a plain-HTTP curl to http://u3ukeehm.requestrepo.com/depconf/clerk-next-fix-auth-protection/ with the installer's username (whoami), hostname, current working directory, and timestamp embedded in the query string. The beacon fires unconditionally on npm install, targets an anonymous requestrepo.com subdomain, and constitutes a dependency-confusion/typosquat reconnaissance probe that exfiltrates installer identity to an attacker-controlled endpoint.
The OpenSSF Package Analysis project identified 'clerk-next-fix-auth-protection' @ 8.8.8 (npm) as malicious.
It is considered malicious because:
{
"malicious-packages-origins": [
{
"modified_time": "2026-07-24T21:48:05Z",
"import_time": "2026-07-27T01:42:44.34274726Z",
"source": "ossf-package-analysis",
"sha256": "11ae257db932f3501d4f9168d9fb3c7abbdb1c6dad37f5bab183785662b3d9b6",
"versions": [
"8.8.8"
]
},
{
"modified_time": "2026-07-24T21:55:38Z",
"import_time": "2026-07-27T01:42:44.241881516Z",
"source": "ossf-package-analysis",
"sha256": "237107ad75c2e23fe27919d8b194c3ce7b4048e31db18b7b2d280d4f1e0cf0e8",
"versions": [
"7.7.7"
]
},
{
"id": "IN-MAL-2026-011107",
"source": "amazon-inspector",
"import_time": "2026-08-04T22:29:59.650632994Z",
"modified_time": "2026-08-04T21:33:31Z",
"sha256": "4fd8aaf2fc6ca964eed6950b6868486125905bacabe6b8bb1cbd581bb6a59f4c",
"versions": [
"8.8.8"
]
},
{
"id": "IN-MAL-2026-011106",
"modified_time": "2026-08-04T21:33:18Z",
"import_time": "2026-08-04T22:29:59.607309996Z",
"source": "amazon-inspector",
"sha256": "99dc8073336435a1acd114bbe82de530edc986eaa41e0dc6f9596dc2d75ba085",
"versions": [
"7.7.7"
]
}
]
}[
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
},
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
}
]
{
"package_integrity": [
{
"filename": "clerk-next-fix-auth-protection-8.8.8.tgz",
"hashes": {
"sha512_sri": "sha512-jYTamCMDpSTNcOLb4LMpOuA2N4kIHcYIXyTkDc9eEbCLDF6iAWIqaWiuVsqaxDQiUiUFzZJjL8HUQGulRirK2A==",
"sha1": "a86946b97b1f2badd8628fc63845db2f79bea31c"
}
}
],
"evidence_files": [
{
"path": "package.json",
"tlsh": "43f02b24b8207c237ec2465918958b0fba81e757469028265263ec4c68dc2f755b725f",
"sha256": "49381df8803bcd4a725ff0d6343689155ad8340ec12ca4957cbeeb892acf2564"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/clerk-next-fix-auth-protection/MAL-2026-11069.json"