MAL-2026-13744

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@dgn-src-click-to-pay-org/srcdcfreleasecert/MAL-2026-13744.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-13744
Published
2026-08-11T18:50:11Z
Modified
2026-08-11T19:00:11.538201181Z
Summary
Malicious code in @dgn-src-click-to-pay-org/srcdcfreleasecert (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (6c203676b4cd54080189fef8d6740d09a1667f2ba0d939936ee46bd6dda4e15d)

The package's postinstall hook (scripts/check-env.js) executes on npm install and POSTs the package name/version along with the host's platform, architecture, and Node.js version to a hardcoded bare-IP endpoint at http://16-171-38-148.sslip.io:8080/api/install over plain HTTP. The package is published at version 999.0.1 — a sentinel value chosen to outrank legitimate internal versions during resolution — under a scoped organization name evoking a payments vendor (Discover/SRC click-to-pay), while the module body contains only trivial PAN/Luhn helpers. This is the canonical dependency-confusion reconnaissance shape: the squatted scope resolves inside a target build system and the postinstall beacon reports back which internal environments were successfully hijacked, enabling attacker follow-up against those hosts.

Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2026-08-11T18:52:01.394906528Z",
            "id": "IN-MAL-2026-017386",
            "sha256": "6c203676b4cd54080189fef8d6740d09a1667f2ba0d939936ee46bd6dda4e15d",
            "modified_time": "2026-08-11T18:50:11Z",
            "source": "amazon-inspector",
            "versions": [
                "999.0.1"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @dgn-src-click-to-pay-org/srcdcfreleasecert

Package

Name
@dgn-src-click-to-pay-org/srcdcfreleasecert
View open source insights on deps.dev
Purl
pkg:npm/%40dgn-src-click-to-pay-org/srcdcfreleasecert

Affected ranges

Affected versions

999.*
999.0.1

Database specific

cwes
[
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "scripts/check-env.js",
            "tlsh": "9021b7c855fa9c311f5ae18e60eb590a127d5101351fd8b8b09d00412f93abc52f1fec",
            "sha256": "46c5520d3525e4ab6700a4a5b958685cbe75a5e8f0eabee489179a63f4363e9f"
        },
        {
            "path": "package.json",
            "tlsh": "68f055a8e8154c2324c5aa5b0c2742073620ce4b0651bd0d7b97618c479eb7b8eff16c",
            "sha256": "d4be85316e5a6e6760644235515328f2adaf1bdf061086e343eb33e942e30625"
        }
    ],
    "package_integrity": [
        {
            "filename": "srcdcfreleasecert-999.0.1.tgz",
            "hashes": {
                "sha1": "b9f988568613e2594d28d633a6cf90f7539cee1d",
                "sha512_sri": "sha512-ltqK87qQfAlxsV8BjMeg0TXcNplNFSlJTEkKW3mk7b20wMmYoKZ+xt3kr3fy3kPoPu9OZYf0peSOMrF/HPMdBw=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@dgn-src-click-to-pay-org/srcdcfreleasecert/MAL-2026-13744.json"