MAL-2026-11069

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/clerk-next-fix-auth-protection/MAL-2026-11069.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-11069
Published
2026-07-24T21:48:05Z
Modified
2026-08-04T23:04:56.476340306Z
Summary
Malicious code in clerk-next-fix-auth-protection (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (4fd8aaf2fc6ca964eed6950b6868486125905bacabe6b8bb1cbd581bb6a59f4c)

clerk-next-fix-auth-protection@8.8.8 is a typosquat of Clerk/Next.js auth tooling that ships no functional code (declared main index.js is absent from the tarball). Both preinstall and postinstall lifecycle hooks in package.json run a plain-HTTP curl to http://u3ukeehm.requestrepo.com/depconf/clerk-next-fix-auth-protection/ with the installer's username (whoami), hostname, current working directory, and timestamp embedded in the query string. The beacon fires unconditionally on npm install, targets an anonymous requestrepo.com subdomain, and constitutes a dependency-confusion/typosquat reconnaissance probe that exfiltrates installer identity to an attacker-controlled endpoint.

Source: ossf-package-analysis (11ae257db932f3501d4f9168d9fb3c7abbdb1c6dad37f5bab183785662b3d9b6)

The OpenSSF Package Analysis project identified 'clerk-next-fix-auth-protection' @ 8.8.8 (npm) as malicious.

It is considered malicious because:

  • The package executes one or more commands associated with malicious behavior.
Database specific
{
    "malicious-packages-origins": [
        {
            "modified_time": "2026-07-24T21:48:05Z",
            "import_time": "2026-07-27T01:42:44.34274726Z",
            "source": "ossf-package-analysis",
            "sha256": "11ae257db932f3501d4f9168d9fb3c7abbdb1c6dad37f5bab183785662b3d9b6",
            "versions": [
                "8.8.8"
            ]
        },
        {
            "modified_time": "2026-07-24T21:55:38Z",
            "import_time": "2026-07-27T01:42:44.241881516Z",
            "source": "ossf-package-analysis",
            "sha256": "237107ad75c2e23fe27919d8b194c3ce7b4048e31db18b7b2d280d4f1e0cf0e8",
            "versions": [
                "7.7.7"
            ]
        },
        {
            "id": "IN-MAL-2026-011107",
            "source": "amazon-inspector",
            "import_time": "2026-08-04T22:29:59.650632994Z",
            "modified_time": "2026-08-04T21:33:31Z",
            "sha256": "4fd8aaf2fc6ca964eed6950b6868486125905bacabe6b8bb1cbd581bb6a59f4c",
            "versions": [
                "8.8.8"
            ]
        },
        {
            "id": "IN-MAL-2026-011106",
            "modified_time": "2026-08-04T21:33:18Z",
            "import_time": "2026-08-04T22:29:59.607309996Z",
            "source": "amazon-inspector",
            "sha256": "99dc8073336435a1acd114bbe82de530edc986eaa41e0dc6f9596dc2d75ba085",
            "versions": [
                "7.7.7"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / clerk-next-fix-auth-protection

Package

Name
clerk-next-fix-auth-protection
View open source insights on deps.dev
Purl
pkg:npm/clerk-next-fix-auth-protection

Affected ranges

Affected versions

7.*
7.7.7
8.*
8.8.8

Database specific

cwes
[
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    },
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    }
]
indicators
{
    "package_integrity": [
        {
            "filename": "clerk-next-fix-auth-protection-8.8.8.tgz",
            "hashes": {
                "sha512_sri": "sha512-jYTamCMDpSTNcOLb4LMpOuA2N4kIHcYIXyTkDc9eEbCLDF6iAWIqaWiuVsqaxDQiUiUFzZJjL8HUQGulRirK2A==",
                "sha1": "a86946b97b1f2badd8628fc63845db2f79bea31c"
            }
        }
    ],
    "evidence_files": [
        {
            "path": "package.json",
            "tlsh": "43f02b24b8207c237ec2465918958b0fba81e757469028265263ec4c68dc2f755b725f",
            "sha256": "49381df8803bcd4a725ff0d6343689155ad8340ec12ca4957cbeeb892acf2564"
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/clerk-next-fix-auth-protection/MAL-2026-11069.json"