MAL-2026-17415

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/com.epi.e2e_test/MAL-2026-17415.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17415
Published
2026-09-30T13:50:32Z
Modified
2026-09-30T14:30:07Z
Summary
Malicious code in com.epi.e2e_test (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (5a0c1068af335818f2b9d905f2d39ebe594f84a6c63e470877692554bc95103b)

package.json declares a preinstall script that runs index.js on npm install. index.js collects host identifiers (os.homedir(), os.hostname(), os.userInfo().username, dns.getServers(), current working directory) along with the contents of the package.json and POSTs them over HTTPS to the hardcoded external host meta.brs.cx. This behavior fires automatically on install with no user interaction, and the collected data is characteristic of dependency-confusion / internal-name reconnaissance beacons used to identify targets for follow-on attacks.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-020822",
            "import_time":  "2026-09-30T14:21:25.191390953Z",
            "modified_time":  "2026-09-30T13:50:32Z",
            "sha256":  "5a0c1068af335818f2b9d905f2d39ebe594f84a6c63e470877692554bc95103b",
            "source":  "amazon-inspector",
            "versions":  [
                "1.2.2"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / com.epi.e2e_test

Package

Name
com.epi.e2e_test
View open source insights on deps.dev
Purl
pkg:npm/com.epi.e2e_test

Affected ranges

Affected versions

1.*
1.2.2

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "index.js",
            "sha256":  "6997cc0dbb734648576645638c3354b176fdd0f7ad89055626d752474a96237c",
            "tlsh":  "c711c0e4c1e123600dba55c47899d00816aad737780e6cd8f68d03d04fceabc70b2af1"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "com.epi.e2e_test-1.2.2.tgz",
            "hashes":  {
                "sha1":  "1915501cc527d33f0e9248146554cd01cc2d7311",
                "sha512_sri":  "sha512-HMkc/9uIkxiPGGLJGjhx0pREJCPWQ4U9zyvTX8tWENoiQN7Ui1nHVxDAKB7cYH13dv6uWHWxPFa4ALQwltl0nA=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/com.epi.e2e_test/MAL-2026-17415.json"