MAL-2026-16357

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@asdfaskdjfksadhfkasf/nadaver2/MAL-2026-16357.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-16357
Published
2026-09-21T19:06:07Z
Modified
2026-09-21T21:46:05Z
Summary
Malicious code in @asdfaskdjfksadhfkasf/nadaver2 (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (ffa99497d70b8eae199242d576c111b7b351efcf5d81d613e3f7b43eec257f27)

The package declares a preinstall lifecycle script that executes index.js on npm install. index.js uses child_process.exec to run a curl command whose URL embeds $(hostname) and $(whoami) as subdomains of sgc6vj7rjciuailqx2kfebc7pyvpjk79.oastify.com, a Burp Collaborator (OAST) host. On install, the installer's hostname and username are transmitted to that attacker-controlled destination via DNS resolution and HTTP. The package name is a random alphanumeric scope with no legitimate functionality; the sole observable behavior is host reconnaissance exfiltration at install time. This is the canonical dependency-confusion / OAST recon payload shape.

Source: ossf-package-analysis (278821d7a9d245a4193d8536c0b127f61cf1b13335dfe91abaefece6b908a57e)

The OpenSSF Package Analysis project identified '@asdfaskdjfksadhfkasf/nadaver2' @ 102.0.0 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

  • The package executes one or more commands associated with malicious behavior.

Database specific
{
    "malicious-packages-origins":  [
        {
            "import_time":  "2026-09-21T19:14:55.95687311Z",
            "modified_time":  "2026-09-21T19:06:07Z",
            "sha256":  "278821d7a9d245a4193d8536c0b127f61cf1b13335dfe91abaefece6b908a57e",
            "source":  "ossf-package-analysis",
            "versions":  [
                "102.0.0"
            ]
        },
        {
            "id":  "IN-MAL-2026-020277",
            "import_time":  "2026-09-21T21:37:44.891663209Z",
            "modified_time":  "2026-09-21T21:28:21Z",
            "sha256":  "ffa99497d70b8eae199242d576c111b7b351efcf5d81d613e3f7b43eec257f27",
            "source":  "amazon-inspector",
            "versions":  [
                "102.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @asdfaskdjfksadhfkasf/nadaver2

Package

Name
@asdfaskdjfksadhfkasf/nadaver2
View open source insights on deps.dev
Purl
pkg:npm/%40asdfaskdjfksadhfkasf/nadaver2

Affected ranges

Affected versions

102.*
102.0.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "index.js",
            "sha256":  "f3f3fe5f70c55104ec31c61a56f4c35001baa21e83a076f89435486d548831b8",
            "tlsh":  "11e0c00508f6543732a21850bd2e141a79434a11123bf182a8ce871023c0a84d9051d9"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "nadaver2-102.0.0.tgz",
            "hashes":  {
                "sha1":  "381f5eb0bb9cea2aec896f71481ae60ae2d8a880",
                "sha512_sri":  "sha512-4++U6OVuH8qMG3KXtAPXRQgW4oKnBY333nJtTeZxfezGtPtzp7BUHBo8DnLNT7k0K4leBs/H9txJZ1XnsJrzvA=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@asdfaskdjfksadhfkasf/nadaver2/MAL-2026-16357.json"