-= Per source details. Do not edit below this line.=-
bcc-design-icons@9999.0.0 declares a postinstall script node./notify.js that runs automatically on npm install. The script performs an HTTP GET to the hardcoded bare-IP endpoint http://91.201.215.48:8000/npm-poc-bcc with query parameters containing os.hostname() and the package name. The 9999.0.0 version, absence of any icon-library functionality expected from the package name, and callback-to-bare-IP shape match a dependency-confusion attack that identifies internal/private installers to the operator. Hostname is host-identifying data exfiltrated to an attacker-controlled destination without any installer opt-in.
{
"malicious-packages-origins": [
{
"import_time": "2026-08-18T05:13:46.108240238Z",
"sha256": "8f25ef58a44d6da495f8f9cd06686303901d391069000f5a10d09694b68241e2",
"modified_time": "2026-08-18T04:46:52Z",
"source": "amazon-inspector",
"id": "IN-MAL-2026-017986",
"versions": [
"9999.0.0"
]
}
]
}"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bcc-design-icons/MAL-2026-14119.json"
{
"evidence_files": [
{
"sha256": "11ce834d0ec3450f68125c12032da2dceec8375f5d6780f6ae45e236b75e0e67",
"path": "notify.js",
"tlsh": "80f02eed81f4915831f249c8b2674562f211c151b84bd6c1fbcd22612fd6c66c6f34e8"
}
],
"package_integrity": [
{
"filename": "bcc-design-icons-9999.0.0.tgz",
"hashes": {
"sha1": "63ddc15c1baf00aed847600529437a6dbcd7373d",
"sha512_sri": "sha512-PAKsS2JpNpTH7j2ixGl2C2aXS2uwhYqR89dDxkwSk7bUaI0TCAtf2YwHaXyd4bIfbINBvwzrICfMAsfUPeyIdA=="
}
}
]
}
[
{
"name": "Embedded Malicious Code",
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature."
}
]