-= Per source details. Do not edit below this line.=-
The package's postinstall script POSTs installer metadata (package name/version, platform, arch, Node version, timestamp) over plain HTTP to a hardcoded sslip.io-wrapped bare IP at http://16-171-38-148.sslip.io:8080/api/install. The scoped name mimics an internal corporate org (@dgn-src-click-to-pay-org) and the version is inflated to 374.0.0, matching the canonical dependency-confusion pattern: a lure package published to the public registry to be resolved by internal build systems that mistakenly reach out for a namespace they expected to be private, with a callback that reports successful installs to an attacker-controlled endpoint. The beacon fires automatically on npm install with no user action, revealing internal build host presence and confirming which corporate targets are vulnerable to further dependency-confusion payloads.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-017386",
"import_time": "2026-08-11T18:52:01.394906528Z",
"modified_time": "2026-08-11T18:50:11Z",
"sha256": "6c203676b4cd54080189fef8d6740d09a1667f2ba0d939936ee46bd6dda4e15d",
"source": "amazon-inspector",
"versions": [
"999.0.1"
]
},
{
"id": "IN-MAL-2026-017713",
"import_time": "2026-08-13T22:20:21.698110377Z",
"modified_time": "2026-08-13T22:03:33Z",
"sha256": "2284b9966871244eb99dd61230f6b17e6b2fb315484fb2b3048c51a780820a1f",
"source": "amazon-inspector",
"versions": [
"374.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "scripts/check-env.js",
"sha256": "46c5520d3525e4ab6700a4a5b958685cbe75a5e8f0eabee489179a63f4363e9f",
"tlsh": "9021b7c855fa9c311f5ae18e60eb590a127d5101351fd8b8b09d00412f93abc52f1fec"
},
{
"path": "package.json",
"sha256": "d4be85316e5a6e6760644235515328f2adaf1bdf061086e343eb33e942e30625",
"tlsh": "68f055a8e8154c2324c5aa5b0c2742073620ce4b0651bd0d7b97618c479eb7b8eff16c"
}
],
"package_integrity": [
{
"filename": "srcdcfreleasecert-999.0.1.tgz",
"hashes": {
"sha1": "b9f988568613e2594d28d633a6cf90f7539cee1d",
"sha512_sri": "sha512-ltqK87qQfAlxsV8BjMeg0TXcNplNFSlJTEkKW3mk7b20wMmYoKZ+xt3kr3fy3kPoPu9OZYf0peSOMrF/HPMdBw=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@dgn-src-click-to-pay-org/srcdcfreleasecert/MAL-2026-13744.json"