-= Per source details. Do not edit below this line.=-
tempo-modules@99.0.1 is a dependency-confusion attack package. The package.json preinstall hook executes poc.js, which on every npm install harvests hostname, username, full network configuration (ipconfig/ip a/resolv.conf), git remote, parent package.json, and CI pipeline definitions (.gitlab-ci.yml,.github/workflows, Jenkinsfile, azure-pipelines.yml), plus whoami/id output. It then iterates process.env and selects any key containing TOKEN, AWS, AZURE, NPM, GITHUB, GITLAB, CI, JENKINS, BUILD, WALMART, etc. — bulk credential scraping of cloud and CI tokens. The collected JSON is POSTed to https://d8a5d9pon5bugoc35cngp9hcregcqyezu.oast.me/ (an Interactsh out-of-band collector), with a hex-encoded host-user identifier additionally DNS-exfiltrated. The package is published at version 99.0.1 with an internal-sounding name to win dependency-confusion resolution against an organization's private registry; the description self-identifies as a 'Dependency Confusion PoC' for a bug-bounty program, but the published artifact harms any installer that resolves this name. Multiple independent block signals stack: lifecycle preinstall outbound exfil, bulk credential harvest of CI/cloud tokens, and dependency-confusion version inflation.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-004688",
"import_time": "2026-05-26T05:53:05.48142811Z",
"modified_time": "2026-05-25T14:16:02Z",
"sha256": "6ad4276e2eafbe6d7040f94ac546ec20e7ac211e1e5906964c25f581a519d183",
"source": "amazon-inspector",
"versions": [
"99.0.1"
]
},
{
"id": "IN-MAL-2026-004690",
"import_time": "2026-05-26T05:53:05.683197991Z",
"modified_time": "2026-05-25T14:16:03Z",
"sha256": "7fe7b908b9ebd546f11dc133ed56c3eb783c144f258be19e3e9e9a81770f09b2",
"source": "amazon-inspector",
"versions": [
"99.0.1"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"domains": [
"d8a5d9pon5bugoc35cngp9hcregcqyezu.oast.me",
"tempo-modules-7363616e2d66363038363261313036.d8a5d9pon5bugoc35cngp9hcregcqyezu.oast.me"
],
"evidence_files": [
{
"path": "poc.js",
"sha256": "9dd3b4f8639851060276bb073c73f2aa9f0f6e18fd192d7cc7033fb6750cf502",
"tlsh": "4071c7d482fa1e3022aa75b1f5cd000522d7d3933206f9d4798c1a919f9f8b482f67bd"
},
{
"path": "package.json",
"sha256": "951454c50101c85b32a8d3c90d0aca1099807b6fa18229a23cee2885cff19dab",
"tlsh": "1ae07d78146010231ad8c3fa15b644479128dd0b51186c1d0757348c42aebb301bfb5d"
}
],
"package_integrity": [
{
"filename": "tempo-modules-99.0.1.tgz",
"hashes": {
"sha1": "e389b3127053cb950d1d97eeae078e787bcf2443",
"sha512_sri": "sha512-eDJHmsUH1H5hM2v8XDs+iqtb/XN8IHqARJd32htlVqQr+NjBlitkEGcFndZ9Lx9JkcuXsuwldKsEkAWw5ylU3Q=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/tempo-modules/MAL-2026-4687.json"