-= Per source details. Do not edit below this line.=-
Version 99.0.0 of this package targets an internal-looking npm scope and ships a postinstall.js that, on every npm install, reads os.hostname(), os.userInfo().username, process.version, and the package name and transmits them to the third-party OAST domain d84t2rmqt3fpphmbii3gf9sdi63c3gkp7.oast.online over both HTTP GET (port 80) and DNS lookup. The package's main entry (index.js) is a placeholder stub containing only a ConsentsStatus enum with a comment self-describing it as a PoC stub mirroring the real package's API. The combination of an inflated 99.0.0 version, a hollow API surface, and an unconditional install-time beacon to an interactsh out-of-band exfiltration host on a scope that resembles an internal Pluxee namespace is a textbook dependency-confusion attack: any build system misresolving the internal name to this public package leaks host identity to the attacker's OAST listener.
The OpenSSF Package Analysis project identified '@pluxee-connect/account-db-api-client' @ 99.0.0 (npm) as malicious.
It is considered malicious because:
{
"malicious-packages-origins": [
{
"import_time": "2026-05-17T15:26:55.415931472Z",
"modified_time": "2026-05-17T14:51:10Z",
"sha256": "b7d101dbff5c071f3bab34e97f3d340e0b52caa00e38ef82e630864d44a7dce3",
"source": "ossf-package-analysis",
"versions": [
"99.0.0"
]
},
{
"import_time": "2026-05-19T17:50:18.539159308Z",
"modified_time": "2026-05-19T16:47:48Z",
"sha256": "5bf0b2245dd636268ec39543616b01a112a5fefdcd1e0bb3871253c9d6c66f16",
"source": "amazon-inspector",
"versions": [
"99.0.0"
]
},
{
"id": "IN-MAL-2026-003453",
"import_time": "2026-05-26T05:50:40.334678781Z",
"modified_time": "2026-05-20T03:59:16Z",
"sha256": "2f7a7dc221fc21232e339e65cab2b61e23dbfe8d558f180655baef639074ca64",
"source": "amazon-inspector",
"versions": [
"99.0.0"
]
},
{
"id": "IN-MAL-2026-003452",
"import_time": "2026-05-26T05:50:40.227691547Z",
"modified_time": "2026-05-20T03:59:16Z",
"sha256": "49a36af66b1c55fbf7a78529c1fe2d15b819cef018300a03cdc8e0a1b59f36c9",
"source": "amazon-inspector",
"versions": [
"99.0.0"
]
},
{
"id": "IN-MAL-2026-003607",
"import_time": "2026-05-26T05:50:57.473949943Z",
"modified_time": "2026-05-20T19:44:13Z",
"sha256": "665582dfdf3ec83c50aced3777adb2b4a51ddc054cd07b9af0dd4d8e28896cec",
"source": "amazon-inspector",
"versions": [
"99.0.1"
]
},
{
"id": "IN-MAL-2026-003606",
"import_time": "2026-05-26T05:50:57.331061468Z",
"modified_time": "2026-05-20T19:44:12Z",
"sha256": "9104569f9f07e32685849b839c9620452f9ae03afc4706147f999a5bd6ae43fe",
"source": "amazon-inspector",
"versions": [
"99.0.1"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"domains": [
"scan-5d9d8f7cef77.scan.d84t2rmqt3fpphmbii3gf9sdi63c3gkp7.oast.online",
"d84t2rmqt3fpphmbii3gf9sdi63c3gkp7.oast.online"
],
"evidence_files": [
{
"path": "postinstall.js",
"sha256": "1780ded65508f58b622451654afff15cd13d32bb40e3136c40d3e2338d407b3f",
"tlsh": "29016dd485e9d63019fb15d8b79b481e90dbe202795acc80f5be42d00f6753986619b8"
},
{
"path": "index.js",
"sha256": "730c728f317c8d0daed1c41bfc9847995f9898183110aa9ac19feb0de5fa06c8",
"tlsh": "a5d0959392d61314694308d0f10fcd43bf41147213050b88060cc14cd4f8acd3cb35d4"
}
],
"package_integrity": [
{
"filename": "account-db-api-client-99.0.0.tgz",
"hashes": {
"sha1": "8fbb62a9a87cacf1635ed84b16675cd20f3a4790",
"sha512_sri": "sha512-uyuSxszyI+Elrw+2WDI9hxQn3D24zN1ADL8gMX2IV7RKpC0j8CfiWGM3NN2PsmjFhpjXk3bkUbg1IvczMhV63g=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@pluxee-connect/account-db-api-client/MAL-2026-3810.json"