-= Per source details. Do not edit below this line.=-
On npm install, the preinstall hook executes index.js which collects host identity data (os.hostname(), os.userInfo().username, os.homedir(), current working directory, DNS server list) together with the full package.json contents and POSTs them to the hardcoded external endpoint https://eogo57c0daum9d3.m.pipedream.net. The behavior fires unconditionally at install time on every installer machine. A code comment references burpcollaborator/Interactsh-style beaconing, consistent with dependency-confusion reconnaissance: the beacon fires when a private internal package name is inadvertently resolved from the public npm registry, revealing the victim's internal infrastructure to whoever controls the pipedream endpoint. The exfiltrated fields identify the installer's host, user account, filesystem layout, network DNS configuration, and internal package/dependency graph.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-017652",
"import_time": "2026-08-13T17:24:46.043024512Z",
"sha256": "008641dff89b7e4b86993671997e965642fab5620006c5ece0827f0fe72fe0d9",
"versions": [
"1.1.0"
],
"source": "amazon-inspector",
"modified_time": "2026-08-13T17:20:59Z"
}
]
}[
{
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code",
"cweId": "CWE-506"
}
]
{
"evidence_files": [
{
"path": "index.js",
"tlsh": "d811add985e2236009b659c47899d00816aad737790e6de8b58d47d40fceafc70b3af1",
"sha256": "0b3de46126a6c8c5d68464db99870ca04c9a54af068c9f9ac81b59ebb7386f71"
}
],
"package_integrity": [
{
"filename": "cilm-ui-commons-1.1.0.tgz",
"hashes": {
"sha512_sri": "sha512-KztyDRk+C2+sOeNP44MA3KyX0YsAV1SQeQCD4qLmTyQRmjT0PusZzSBJo0pPbDqWUmPSQmoPmZ0KFC89KTkhsg==",
"sha1": "e31f1374562ef65ea0a0c77c8bb69015db8dbf43"
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/cilm-ui-commons/MAL-2026-13943.json"