MAL-2026-11430

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/list-issue-predecessor-dependencies-block/MAL-2026-11430.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-11430
Published
2026-08-02T19:04:25Z
Modified
2026-08-04T22:05:08.835232726Z
Summary
Malicious code in list-issue-predecessor-dependencies-block (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (bbd4d4e3aa51ec1a7ebc0a0d4f728698503432546f139f67998849f8fff9b614)

npm package list-issue-predecessor-dependencies-block@99.0.0 auto-executes index.js from three lifecycle hooks (preinstall, install, postinstall) on npm install. The script collects installer identity and environment reconnaissance — os.hostname(), os.platform(), username, current working directory, output of shell commands (whoami, id, hostname -I via childprocess), CI environment variables (GITHUB*, GITLAB_*, JENKINS_*, etc.), AWS/GCP/Azure/Kubernetes cloud-metadata indicators, enumerated names of environment variables matching /KEY|SECRET|TOKEN|PASS|CRED|AUTH|API_|PRIVATE/i, and a boolean flag for the presence of NPMTOKEN / NODEAUTH_TOKEN — and exfiltrates it to the hardcoded Interactsh collaborator qtmetsrtvaujwklywbgw2wihc2lebzu0n.oast.fun via DNS lookups (dns.resolve of labeled subdomains), HTTPS POST to /depconf, and HTTP POST. The high version number (99.0.0) and generic internal-sounding package name are the standard dependency-confusion shape used to override private registry packages with a public squat.

Source: ossf-package-analysis (0f74d699bfc5fcf83c6f2864f93ecd41d3d9f8613f45f6bfb3b6dd5eeb7a880e)

The OpenSSF Package Analysis project identified 'list-issue-predecessor-dependencies-block' @ 99.0.0 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

  • The package executes one or more commands associated with malicious behavior.

Database specific
{
    "malicious-packages-origins": [
        {
            "versions": [
                "99.0.0"
            ],
            "import_time": "2026-08-02T19:31:07.083609961Z",
            "sha256": "0f74d699bfc5fcf83c6f2864f93ecd41d3d9f8613f45f6bfb3b6dd5eeb7a880e",
            "modified_time": "2026-08-02T19:04:25Z",
            "source": "ossf-package-analysis"
        },
        {
            "versions": [
                "99.0.0"
            ],
            "sha256": "bbd4d4e3aa51ec1a7ebc0a0d4f728698503432546f139f67998849f8fff9b614",
            "import_time": "2026-08-04T21:33:16.590765945Z",
            "id": "IN-MAL-2026-011095",
            "modified_time": "2026-08-04T21:31:46Z",
            "source": "amazon-inspector"
        }
    ]
}
References
Credits

Affected packages

npm / list-issue-predecessor-dependencies-block

Package

Name
list-issue-predecessor-dependencies-block
View open source insights on deps.dev
Purl
pkg:npm/list-issue-predecessor-dependencies-block

Affected ranges

Affected versions

99.*
99.0.0

Database specific

indicators
{
    "package_integrity": [
        {
            "filename": "list-issue-predecessor-dependencies-block-99.0.0.tgz",
            "hashes": {
                "sha512_sri": "sha512-26Ez1VrYcWuoeBIXEn1hhtBGMhD8X1ZKj6KJ1QJ85nVyfdk3KG3Cxj/3lOuDFDSCZ4/AeDO4XfjR3cjxo7fMKg==",
                "sha1": "b4f7f998cdbd6ecbaec68423d775db1b6b90f0be"
            }
        }
    ],
    "evidence_files": [
        {
            "path": "index.js",
            "sha256": "309ba9e59f80bbda4cc0c4f3d09c2eeee9890b57c40e724c81b937bb3e108502",
            "tlsh": "937186d6a7fe0a2255e373e0309b081274abd1276345f4f0b55650293fbd62542b39fe"
        },
        {
            "tlsh": "b1e020746c15553325f502d5a675940964b18d175144346495d2008ce3af776c07f34e",
            "sha256": "4a571ef812c3d7d6879cd89584766c20f450c5b1f156ca7fd5825fbbc9252a9d",
            "path": "package.json"
        }
    ]
}
cwes
[
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    }
]
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/list-issue-predecessor-dependencies-block/MAL-2026-11430.json"