-= Per source details. Do not edit below this line.=-
Package is published at version 9999.99.99 — the canonical high-version override used in dependency-confusion attacks against private/internal package names — with a description self-identifying as a name referenced in a private repo. On npm install, postinstall.js POSTs JSON to https://ddactic-lab.online/sc/beacon containing package name/version, Node version, OS, CI detection, and the installer's GITHUBREPOSITORY, GITHUBREPOSITORYOWNER, and GITHUBWORKFLOW environment variables when present. A DNS-encoded fallback is also emitted to subdomains of b.ddactic-lab.online to bypass HTTP egress filtering. The package's library entry point is a no-op self-require; its sole functional behavior is the install-time recon beacon. Installer harm: private repository slugs, owner names, and workflow identifiers leak from CI pipelines to an attacker-controlled domain on every install, identifying which organizations are vulnerable to follow-on dependency-confusion attacks against this name.
{
"malicious-packages-origins": [
{
"source": "amazon-inspector",
"sha256": "9533aa7d902b057e81b29616867dc5c0c48ee5593ae48ee7954f19babf07cbc0",
"modified_time": "2026-06-09T16:04:42Z",
"import_time": "2026-06-09T16:59:43.987298955Z",
"versions": [
"9999.99.99"
],
"id": "IN-MAL-2026-004950"
},
{
"source": "amazon-inspector",
"sha256": "fd4381fd77419441a2eefe6b22adef6c9f5adfe1b92be5d071abd5908fdf8647",
"modified_time": "2026-06-09T16:04:42Z",
"import_time": "2026-06-09T16:59:43.948289868Z",
"versions": [
"9999.99.99"
],
"id": "IN-MAL-2026-004949"
}
]
}"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/create-docs-mcp/MAL-2026-5397.json"
{
"evidence_files": [
{
"tlsh": "e241a755829891340fe122c9b852c8165d7bd49633e799f0774d15226fc92bc03b2fdf",
"sha256": "e5c7efaa25bd6fc20c40fe6e39a40957043022e78b5ec6d9ad2b9e49a3ef75c8",
"path": "postinstall.js"
},
{
"tlsh": "1cf027048d2086732ec8768788775186bbb20c479948b81927eb105cabcd9bb10ff52a",
"sha256": "27ff26f080a45f700af7348ac5f4a2e0371f6cf498a23ba89f8cd6eea34e2c45",
"path": "package.json"
},
{
"tlsh": "b4d02ec283fc3721209a9403f4b000a2a8cae08821250368622d92ccf3c0ca0030ad82",
"sha256": "dd75c9c35a798623e1912f8670d0699283adaf7c25e0bc62663e0d07f37d6960",
"path": "index.js"
}
],
"domains": [
"ddactic-lab.online",
"create-docs-mcp.none.e1d4a47f.b.ddactic-lab.online",
"create-docs-mcp.none.e1d4a47f.b.ddactic-lab.online.ec2.internal"
],
"package_integrity": [
{
"filename": "create-docs-mcp-9999.99.99.tgz",
"hashes": {
"sha512_sri": "sha512-nB6LkTpou46mjQqxQ/BdLl9AEXBQDt02V2hXK47jSSRUFUfaDkNQDUgP8tn/sV6hJ4WRQE7w0wqJhpadusqhiQ==",
"sha1": "4d28dd50329d758be40bf9632580de482efeb559"
}
}
]
}
[
{
"name": "Embedded Malicious Code",
"description": "The product contains code that appears to be malicious in nature.",
"cweId": "CWE-506"
}
]