MAL-2026-17542

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@inpeek/odata/MAL-2026-17542.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17542
Published
2026-10-05T03:33:53Z
Modified
2026-10-05T04:15:04Z
Summary
Malicious code in @inpeek/odata (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (dad085b4b3e089d6a6d4e6812c66a8b45f10d40bc4ab39ea7bd0ce850d17ed4b)

@inpeek/odata@99.99.100 is a dependency-confusion placeholder published to the public npm registry on the unregistered @inpeek scope with an inflated version (99.99.100) designed to outrank any internal release of the same name. The package.json declares a postinstall lifecycle hook that executes ping.js on npm install. ping.js performs an unconditional HTTPS GET to the hardcoded collector URL https://webhook.site/bec9d4b2-8f49-451e-84be-2681cb91ebf2, passing the installer's hostname (os.hostname()), platform (os.platform()), and Node.js version (process.version) as query parameters. index.js throws on require, so any accidental consumer breaks loudly after the postinstall beacon has already fired. The package self-labels as a bug-bounty research placeholder, but the install-time dataflow — automatic transmission of installer host identifiers to a third-party collector the installer did not opt into — is the dependency-confusion exploitation shape and reaches any installer whose tooling resolves @inpeek/* from the public registry.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-021003",
            "import_time":  "2026-10-05T03:57:37.953396998Z",
            "modified_time":  "2026-10-05T03:33:53Z",
            "sha256":  "3f7aeb131f69bd5b75c9420a8825c9621e89453f275bc1e198eb62d93400b5ae",
            "source":  "amazon-inspector",
            "versions":  [
                "99.99.102"
            ]
        },
        {
            "id":  "IN-MAL-2026-021005",
            "import_time":  "2026-10-05T03:57:38.085203734Z",
            "modified_time":  "2026-10-05T03:34:13Z",
            "sha256":  "dad085b4b3e089d6a6d4e6812c66a8b45f10d40bc4ab39ea7bd0ce850d17ed4b",
            "source":  "amazon-inspector",
            "versions":  [
                "99.99.100"
            ]
        },
        {
            "id":  "IN-MAL-2026-021029",
            "import_time":  "2026-10-05T03:57:40.048039974Z",
            "modified_time":  "2026-10-05T03:38:01Z",
            "sha256":  "5dd0a249ba1e978f084ca29dc0a5aca7b68da39a5510716ec5d7050bfd031647",
            "source":  "amazon-inspector",
            "versions":  [
                "99.99.99"
            ]
        },
        {
            "id":  "IN-MAL-2026-021004",
            "import_time":  "2026-10-05T03:57:38.018271748Z",
            "modified_time":  "2026-10-05T03:34:03Z",
            "sha256":  "af0f490d6d86c37f78a097c8bac2644d66355151bf051fae9bd5e1f021d0d6db",
            "source":  "amazon-inspector",
            "versions":  [
                "99.99.101"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @inpeek/odata

Package

Name
@inpeek/odata
View open source insights on deps.dev
Purl
pkg:npm/%40inpeek/odata

Affected ranges

Affected versions

99.*
99.99.99
99.99.100
99.99.101
99.99.102

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "evidence_files":  [
        {
            "path":  "ping.js",
            "sha256":  "62e646e3c33a93cdbd7a45a82bc88a2fc79dff768f2a98c67aedc0bf517fc795",
            "tlsh":  "773187bf2651477017e802e87355745ad783f11ad8511dc0b9cf139847c15eb22216f3"
        },
        {
            "path":  "package.json",
            "sha256":  "f172accb07ca4abf3bff0583e1d04e59afb7ea7939a71c110d9a1b46b1061f5b",
            "tlsh":  "b8f0ac6c99249d7222ec46e9083a5041f1256e8fd850bc4636db100d2b5e5eb52bc26e"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "odata-99.99.102.tgz",
            "hashes":  {
                "sha1":  "1e47bf1a874eb1c8a3f6502408058e1e827a117d",
                "sha512_sri":  "sha512-9kGKMd4YlGRDSyP08pjP03dl1QDo9pOsPzFTnXL7/TUlHqkTGRffAo/YYPm4/Zaxi/loU5IHPVJdF/zxgSOKsw=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@inpeek/odata/MAL-2026-17542.json"