MAL-2026-17437

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@bluewin/utils/MAL-2026-17437.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17437
Published
2026-10-01T02:40:08Z
Modified
2026-10-02T05:01:12Z
Summary
Malicious code in @bluewin/utils (npm)
Details

@bluewin/utils is a dependency-confusion package: it describes itself as a "PoC package for dependency confusion testing" and claims the @bluewin scope, so a build that resolves that scope from the public registry runs its code instead of the intended private package. Its postinstall script runs node postinstall.js on npm install, which sends an HTTPS request to https://5w2cezr3af2i0rvm72x74empvg18pzdo.oastify.com/bluewin/utils, a Burp Collaborator endpoint, disclosing the installing host's IP address and that it installed the package. It collects no further data, but unreviewed code from an outside publisher has run with the installing user's privileges. The npm account securityresearch1 published it on 2026-10-01.

Database specific
{
    "iocs":  {
        "domains":  [
            "5w2cezr3af2i0rvm72x74empvg18pzdo.oastify.com"
        ],
        "files":  [
            {
                "digests":  {
                    "sha256":  "628e04ce4e3165269e4505b10af93a2df7f689fad6bcbf49409d7be7e18bf300"
                },
                "note":  "postinstall script: node postinstall.js",
                "paths":  [
                    "package.json"
                ],
                "source":  "PACKAGE_ARCHIVE"
            },
            {
                "digests":  {
                    "sha256":  "68324659e177d6de76125da39ab3ca96e27a9d3890692a12a652c18471163770"
                },
                "note":  "Executed by the postinstall script of @bluewin/utils@1.0.0.",
                "paths":  [
                    "postinstall.js"
                ],
                "source":  "PACKAGE_ARCHIVE"
            }
        ],
        "urls":  [
            "https://5w2cezr3af2i0rvm72x74empvg18pzdo.oastify.com/bluewin/utils"
        ]
    }
}
References
Credits

Affected packages

npm / @bluewin/utils

Package

Name
@bluewin/utils
View open source insights on deps.dev
Purl
pkg:npm/%40bluewin/utils

Affected ranges

Affected versions

1.*
1.0.0

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@bluewin/utils/MAL-2026-17437.json"