MAL-2026-4587

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/intl-ads/MAL-2026-4587.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-4587
Published
2026-05-25T13:57:57Z
Modified
2026-05-26T06:02:37Z
Summary
Malicious code in intl-ads (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (c7e29be11c53c137c2a24258ae423cf422fefcaad06183d67aa5c895a8fe4801)

On npm install, the package's scripts.preinstall runs poc.js which collects hostname, username, full network configuration (ipconfig/ip a/resolv.conf), id/whoami /all, git remote, parent package.json, and CI configuration files (.gitlab-ci.yml,.github/workflows, Jenkinsfile, azure-pipelines.yml). It then iterates process.env and harvests any variable whose name contains AWS, AZURE, GITHUB, GITLAB, JENKINS, NPM, TOKEN, CI, BUILD, etc. — capturing values, not just names — and POSTs the JSON payload to d8a5d9pon5bugoc35cngp9hcregcqyezu.oast.me over HTTPS, with a DNS callback as a secondary channel. The package self-describes as authorized bug-bounty research targeting Walmart's private namespace via dependency confusion, but the public npm registry has no scope restriction: any developer or CI system that resolves this name will execute the recon and leak credentials. The OAST destination is an Interactsh collector, not a Walmart-owned endpoint, so harvested data leaves any authorized scope. Concrete installer harm: AWS/Azure/GitHub/GitLab/npm tokens present in CI environment are exfiltrated; host fingerprinting enables follow-on attacks.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "IN-MAL-2026-004666",
            "import_time": "2026-05-26T05:53:03.032119287Z",
            "modified_time": "2026-05-25T14:04:48Z",
            "sha256": "0e3ef1ac43fa8e2f7a5e780c59071356afe6c000141639d1964338bf6234e8b0",
            "source": "amazon-inspector",
            "versions": [
                "99.0.1"
            ]
        },
        {
            "id": "IN-MAL-2026-004664",
            "import_time": "2026-05-26T05:53:02.820436739Z",
            "modified_time": "2026-05-25T13:57:58Z",
            "sha256": "74af72febe42133dcf81ad5910fc4ca98293df63ae8f8de60165db1c6fa49832",
            "source": "amazon-inspector",
            "versions": [
                "99.0.0"
            ]
        },
        {
            "id": "IN-MAL-2026-004667",
            "import_time": "2026-05-26T05:53:03.124260823Z",
            "modified_time": "2026-05-25T14:04:48Z",
            "sha256": "943b5422a0d6d362eeecd14087b149836b80a997a347731eeb93a64c1926e7e4",
            "source": "amazon-inspector",
            "versions": [
                "99.0.1"
            ]
        },
        {
            "id": "IN-MAL-2026-004674",
            "import_time": "2026-05-26T05:53:03.855274117Z",
            "modified_time": "2026-05-25T14:09:54Z",
            "sha256": "c7e29be11c53c137c2a24258ae423cf422fefcaad06183d67aa5c895a8fe4801",
            "source": "amazon-inspector",
            "versions": [
                "99.0.2"
            ]
        },
        {
            "id": "IN-MAL-2026-004663",
            "import_time": "2026-05-26T05:53:02.719339662Z",
            "modified_time": "2026-05-25T13:57:57Z",
            "sha256": "e97850316cad977b2e7bc006034b3c7d7ab1aca8ff13f98a49420a2a7a400ee4",
            "source": "amazon-inspector",
            "versions": [
                "99.0.0"
            ]
        },
        {
            "id": "IN-MAL-2026-004675",
            "import_time": "2026-05-26T05:53:03.986537211Z",
            "modified_time": "2026-05-25T14:09:55Z",
            "sha256": "2dad6bce5816c5d7f31035825cfb9f741f6863bca59221dac4308e110256e7d0",
            "source": "amazon-inspector",
            "versions": [
                "99.0.2"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / intl-ads

Package

Affected ranges

Affected versions

99.*
99.0.0
99.0.1
99.0.2

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
indicators
{
    "domains": [
        "d8a56vpon5budaeafq00tsyj88aqd5m7p.oast.pro"
    ],
    "evidence_files": [
        {
            "path": "poc.js",
            "sha256": "8b87b23b345fd282383ca2d4d11a166c5b242639464c71b4bb4d915c1d43a899",
            "tlsh": "ba3165d615f9647036b6f6c0b0d6ad515367e333b54af8e42588094162cf9f141f52e4"
        },
        {
            "path": "package.json",
            "sha256": "55335b51a17b25f8ed7774270dafe46be307c30485360022c576e7a65b162a8f",
            "tlsh": "fce07d781510102316e8c3fa05b65847a128cd0b51086c190b53344c82eeba301bfb5d"
        }
    ],
    "package_integrity": [
        {
            "filename": "intl-ads-99.0.1.tgz",
            "hashes": {
                "sha1": "66916c08686b3fa669e5d2667ff3805ebabe6a1e",
                "sha512_sri": "sha512-pHydKJaMs0R8RifFswa9RW36sD9MeL4+kREJsEUQbS0LxlpueORtpCsvEhq4x7HqkJKkj8I9n/MABwdI0p1mKQ=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/intl-ads/MAL-2026-4587.json"