MAL-2026-17642

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/personio-pipeline-projen/MAL-2026-17642.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17642
Published
2026-10-07T04:52:26Z
Modified
2026-10-07T07:00:05Z
Summary
Malicious code in personio-pipeline-projen (npm)
Details

personio-pipeline-projen presents itself as an authorized dependency-confusion proof-of-concept; the evidence does not identify a copied public package. Its preinstall hook runs on install with node canary.js. The dependency-confusion probe encodes the installing machine's hostname and username, present CI-variable names, and root project and lifecycle identifiers in a DNS label under db2su65ptuma8gfn6ing8e7dx7wp55zit.oast.fun, and sends an HTTPS GET to hrcv3zo9m3z70yr91ssdz669c0ir6ju8.oastify.com. The npm account reaperhackbot256f published it on 2026-10-07 (UTC).

Database specific
{
    "iocs": {
        "domains": [
            "db2su65ptuma8gfn6ing8e7dx7wp55zit.oast.fun",
            "hrcv3zo9m3z70yr91ssdz669c0ir6ju8.oastify.com"
        ],
        "files": [
            {
                "digests": {
                    "sha256": "9047c11dc81dda0e8120f6777cb88678eaa0d7c995adb8d069731ab6b85f9a1e"
                },
                "note": "preinstall script: node canary.js",
                "paths": [
                    "package.json"
                ],
                "source": "PACKAGE_ARCHIVE"
            },
            {
                "digests": {
                    "sha256": "88fdfbfbc5982045f7fdc7a4f6097031b64689d1003c1a592156f37921db63f6"
                },
                "note": "Executed by the preinstall script of personio-pipeline-projen@1.171.31.",
                "paths": [
                    "canary.js"
                ],
                "source": "PACKAGE_ARCHIVE"
            }
        ],
        "urls": [
            "https://hrcv3zo9m3z70yr91ssdz669c0ir6ju8.oastify.com/h"
        ]
    }
}
References
Credits

Affected packages

npm / personio-pipeline-projen

Package

Name
personio-pipeline-projen
View open source insights on deps.dev
Purl
pkg:npm/personio-pipeline-projen

Affected ranges

Affected versions

1.*
1.171.31

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/personio-pipeline-projen/MAL-2026-17642.json"