MAL-2026-17214

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/git-en-boite-logging/MAL-2026-17214.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17214
Published
2026-09-28T14:18:12Z
Modified
2026-09-28T14:30:08Z
Summary
Malicious code in git-en-boite-logging (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (f6ebee9f4428d7f14f6f941438064715c8bece34c5fe6bfedf32bbd8cba226c0)

package.json declares a preinstall lifecycle hook that runs wget to a hardcoded webhook.site collector URL (https://webhook.site/3fcfa5af-1b4e-4556-9d48-26190d02795f/), passing $(whoami), $(hostname), and $(pwd) as query parameters. On npm install, npm invokes the preinstall script automatically, so the installer's OS username, host name, and current working directory are transmitted to an anonymous third-party webhook collector without any user action. This is the canonical dependency-confusion / reconnaissance beacon shape: an otherwise-empty package whose only on-install effect is to phone home installer identity to an attacker-chosen endpoint, typically used to confirm ingress into a target's internal build environment before staging a follow-on payload.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020579",
            "import_time":  "2026-09-28T14:21:43.654845338Z",
            "modified_time":  "2026-09-28T14:18:12Z",
            "sha256":  "f6ebee9f4428d7f14f6f941438064715c8bece34c5fe6bfedf32bbd8cba226c0",
            "source":  "amazon-inspector",
            "versions":  [
                "0.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / git-en-boite-logging

Package

Name
git-en-boite-logging
View open source insights on deps.dev
Purl
pkg:npm/git-en-boite-logging

Affected ranges

Affected versions

0.*
0.0.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "package.json",
            "sha256":  "eeeb7167a98450e8be74ff678e8b1e72ba1c68ed75fd157f1352d5e90dfdfe30",
            "tlsh":  "5f01d334f620b92307c597a15525461bba32fba7da1a6c0deba71259531d8ea0078a18"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "git-en-boite-logging-0.0.0.tgz",
            "hashes":  {
                "sha1":  "9b6320e561bb6b58d363bface8b6c6f90fea6c28",
                "sha512_sri":  "sha512-NpfFTMEfKE1HF+2F7ZE66DoiQj017DTFOa4a1glV0xG0lthw4cwFH6PnFVjERMxGYlnyeUHVEk8q+VxobgInkQ=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/git-en-boite-logging/MAL-2026-17214.json"