MAL-2026-5154

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@customer-threesixty/assets/MAL-2026-5154.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-5154
Published
2026-06-01T08:00:00Z
Modified
2026-06-02T10:46:38.147742274Z
Summary
Malicious code in @customer-threesixty/assets (npm)
Details

Dependency confusion attack campaign targeting Scandinavian telecommunications and digital services organizations (Telenor, Ownit, Vimla, and Customer 360 / C360). Four packages published by the debating0166 npm account use inflated version numbers (99.0.x) to win npm registry resolution over private internal packages of the same names. A shared callback.js executed via the preinstall hook collects system reconnaissance data: hostname, username, working directory, platform, network interfaces, npm registry configuration, and environment variables matching organization-specific and CI/CD patterns (telenor, ownit, vimla, c360, customer, threesixty, maui, CI tokens, pipeline variables) and exfiltrates the payload via HTTP POST to 128.199.50.160:8888/depconf.

This package impersonates @customer-threesixty/assets, an internal package of Customer 360 (C360), a customer experience platform. Version 99.0.1 was published to resolve ahead of any private registry copy.

Database specific
{
    "malicious-packages-origins": null
}
References
Credits

Affected packages

npm / @customer-threesixty/assets

Package

Name
@customer-threesixty/assets
View open source insights on deps.dev
Purl
pkg:npm/%40customer-threesixty%2Fassets

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@customer-threesixty/assets/MAL-2026-5154.json"