-= Per source details. Do not edit below this line.=-
The package's postinstall lifecycle script issues an HTTPS request from the installer's machine to a Cloudflare tunnel at wiki-shared-carlos-exempt.trycloudflare.com on path /token-capture. The request is sent with the Host header spoofed to dependabot-api.githubapp.com and with TLS certificate validation disabled (rejectUnauthorized:false), disguising the callout as legitimate GitHub Dependabot traffic. The destination path name (/token-capture) and the disguise mechanics indicate an install-time beacon to an attacker-controlled listener, firing automatically on npm install.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-017133",
"import_time": "2026-08-07T17:51:00.21610457Z",
"sha256": "1a9ed4acf296e53ad5955f759a0f0692d641781b1bd4e67ada1c116216f96fc3",
"modified_time": "2026-08-07T17:31:24Z",
"versions": [
"0.0.3"
],
"source": "amazon-inspector"
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"package_integrity": [
{
"hashes": {
"sha512_sri": "sha512-+rRUwBXtV9PCak2vAVVCAJMJxGg7riDmJ+5eeNAPFqLOjXyoaGM4jicpBQ0Kb2g4pdZumB0sK37kkd1wz2wEuw==",
"sha1": "616f8a3058b7ce9f77764ac1d04b49cdcdae34bd"
},
"filename": "oidc-bind-canary-0.0.3.tgz"
}
],
"evidence_files": [
{
"path": "postinstall.js",
"sha256": "cdb27a1934933dcb25f9a6a9c4ae00853af9f4c464486990380b47bfb526b977",
"tlsh": "5601eff108e581140df3c5c6605f6277b4238104f849e4a4f6d8839f6fcb859c1178bc"
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@mrbenty8jf1p9y5/oidc-bind-canary/MAL-2026-13626.json"