-= Per source details. Do not edit below this line.=-
The package's postinstall hook (scripts/check-env.js) executes on npm install and POSTs the package name/version along with the host's platform, architecture, and Node.js version to a hardcoded bare-IP endpoint at http://16-171-38-148.sslip.io:8080/api/install over plain HTTP. The package is published at version 999.0.1 — a sentinel value chosen to outrank legitimate internal versions during resolution — under a scoped organization name evoking a payments vendor (Discover/SRC click-to-pay), while the module body contains only trivial PAN/Luhn helpers. This is the canonical dependency-confusion reconnaissance shape: the squatted scope resolves inside a target build system and the postinstall beacon reports back which internal environments were successfully hijacked, enabling attacker follow-up against those hosts.
{
"malicious-packages-origins": [
{
"import_time": "2026-08-11T18:52:01.394906528Z",
"id": "IN-MAL-2026-017386",
"sha256": "6c203676b4cd54080189fef8d6740d09a1667f2ba0d939936ee46bd6dda4e15d",
"modified_time": "2026-08-11T18:50:11Z",
"source": "amazon-inspector",
"versions": [
"999.0.1"
]
}
]
}[
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
}
]
{
"evidence_files": [
{
"path": "scripts/check-env.js",
"tlsh": "9021b7c855fa9c311f5ae18e60eb590a127d5101351fd8b8b09d00412f93abc52f1fec",
"sha256": "46c5520d3525e4ab6700a4a5b958685cbe75a5e8f0eabee489179a63f4363e9f"
},
{
"path": "package.json",
"tlsh": "68f055a8e8154c2324c5aa5b0c2742073620ce4b0651bd0d7b97618c479eb7b8eff16c",
"sha256": "d4be85316e5a6e6760644235515328f2adaf1bdf061086e343eb33e942e30625"
}
],
"package_integrity": [
{
"filename": "srcdcfreleasecert-999.0.1.tgz",
"hashes": {
"sha1": "b9f988568613e2594d28d633a6cf90f7539cee1d",
"sha512_sri": "sha512-ltqK87qQfAlxsV8BjMeg0TXcNplNFSlJTEkKW3mk7b20wMmYoKZ+xt3kr3fy3kPoPu9OZYf0peSOMrF/HPMdBw=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@dgn-src-click-to-pay-org/srcdcfreleasecert/MAL-2026-13744.json"