-= Per source details. Do not edit below this line.=-
com.db.dbk.ui-forms@99.0.1 is a version-inflated package published to the public npm registry under a scope that resembles an internal namespace. Its package.json declares preinstall: node index.js, which runs automatically on npm install. index.js collects host identifiers (os.hostname(), os.platform(), os.userInfo(), homedir, network interfaces) and the output of shell commands (uname, id, whoami) via child_process, and enumerates process.env for keys matching /key|token|secret|pass|auth|cred|npm|ci|build|jenkins|github|gitlab|aws|azure/i. The collected payload is POSTed via https.request/http.request to the hardcoded interactsh callback host ycwyyoimdcluajepubahl0tpb7943a2z4.oast.fun at path /dcf/<pkg>, with a base64-chunked copy also emitted via DNS lookups to the same host. The package.json self-describes as a dependency confusion proof of concept; the installer-side behavior is exfiltration regardless of that framing.
{
"malicious-packages-origins": [
{
"sha256": "8c06da3e977cc6beaf2de938ad317573d53bbb6574a537e5f28e5f2addafbba5",
"id": "IN-MAL-2026-014824",
"modified_time": "2026-08-05T12:57:34Z",
"source": "amazon-inspector",
"import_time": "2026-08-05T13:08:49.358634847Z",
"versions": [
"99.0.0"
]
},
{
"sha256": "c74649b28994f970d4972ffb8708378b355186eb729bf2e4c45d6acd16346e5d",
"id": "IN-MAL-2026-014822",
"modified_time": "2026-08-05T12:57:17Z",
"import_time": "2026-08-05T13:08:49.13585634Z",
"source": "amazon-inspector",
"versions": [
"99.0.1"
]
}
]
}{
"evidence_files": [
{
"sha256": "2684afae7cee8ca5e83b9fe92cecd0060a6792e4e4527a981bd882e0f4cb8cc5",
"path": "index.js",
"tlsh": "0f0110f0a1f462f03dbd98c0a8665b1512a3c6137986fce0f68802a45f8eaf885b24d5"
},
{
"sha256": "9191a57f8823320ba4587b4f7b65544c44d70b84dda07432a10aaf2a6c613bf1",
"path": "package.json",
"tlsh": "0ef05c3c9d6090331ee045d069b5964a16778c2b4b09ac74eb53014c55abfe621bb29d"
}
],
"package_integrity": [
{
"hashes": {
"sha512_sri": "sha512-ipU8euL04depqVMbH9F12m58r74199p87xuJmwOOKBhBnNbFfK/ouBFw2+AxjlGanj/9w60v7rn4ZoGTcEo3eA==",
"sha1": "49453367167b0df38a514b8866a5c099110396aa"
},
"filename": "com.db.dbk.ui-forms-99.0.0.tgz"
}
]
}
[
{
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506"
},
{
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506"
}
]
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/com.db.dbk.ui-forms/MAL-2026-12355.json"