-= Per source details. Do not edit below this line.=-
On npm install, the package's preinstall lifecycle hook runs node index.js, which collects installer-side identifiers — os.hostname(), os.userInfo().username, __dirname, process.cwd(), and the package name — and exfiltrates them through two channels. First, the JSON payload is hex-encoded into DNS labels and resolved under *.d8jbmnsqcfu78dfs8vdg34ohqhirb4pbg.oast.live, an out-of-band collector. Second, the same JSON is POSTed to a bare IP http://172.201.213.59:9090/c. Neither destination matches any documented vendor SDK endpoint. The package metadata reinforces malicious intent: the scope @klapp-login-platform resembles an internal namespace, the description is security research, and the version 99.0.2 is inflated to win dependency-confusion resolution against a private package. Installing the package immediately leaks host identity to attacker-controlled infrastructure.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-005069",
"import_time": "2026-06-09T17:45:52.557225152Z",
"modified_time": "2026-06-09T17:35:09Z",
"sha256": "3b3bc8633d15b44abc90074d3362fd9399f53d10a88e24264caee9d924a72bb6",
"source": "amazon-inspector",
"versions": [
"99.0.2"
]
},
{
"id": "IN-MAL-2026-005070",
"import_time": "2026-06-09T17:45:52.604032739Z",
"modified_time": "2026-06-09T17:35:09Z",
"sha256": "4ae85072d8a51ca0d5080df8308f6bdc17112f8245cb5524e8419bb7dadf71bf",
"source": "amazon-inspector",
"versions": [
"99.0.2"
]
},
{
"id": "IN-MAL-2026-005126",
"import_time": "2026-06-09T18:50:17.819553446Z",
"modified_time": "2026-06-09T17:50:20Z",
"sha256": "1a1c21c478fd309e16577b1d023bcc82834075d2b8f6b27ef867764c7db7c3f6",
"source": "amazon-inspector",
"versions": [
"99.0.0"
]
},
{
"id": "IN-MAL-2026-005127",
"import_time": "2026-06-09T18:50:17.877710262Z",
"modified_time": "2026-06-09T17:50:20Z",
"sha256": "e8695fc1070f506a7aba7fc8895f25d14477e685da821196df6b59b027b65db0",
"source": "amazon-inspector",
"versions": [
"99.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"domains": [
"7b2268223a227363616e2d386234653036633064633634222c2275223a22.7363616e222c2264223a222f686f6d652f7363616e2f6e6f64655f6d6f64.756c65732f406b6c6170702d6c6f67696e2d706c6174666f726d2f6e6174.d8jbmnsqcfu78dfs8vdg34ohqhirb4pbg.oast.live"
],
"evidence_files": [
{
"path": "index.js",
"sha256": "c1db02bd41e4eb1d1b347f54a8eae90ed9e44805a5d4a34d04a85bdcb76e4c02",
"tlsh": "e0f00ce162b0d0fd8b708580ecd4668092b7c252b00288f4dc8d0ece0ac28e05d76ab1"
},
{
"path": "package.json",
"sha256": "8f45118b065eba7acc7aae228595a6e7f47dcdc796de12119a3dc64b9705d1d3",
"tlsh": "77d022380b31b83a076143f0acb6ac8ca0f8c31840808d1c4de740b485b17f8809d022"
}
],
"package_integrity": [
{
"filename": "native-sdk-99.0.2.tgz",
"hashes": {
"sha1": "ffea4b3118588a5c1602e95551c5a0cdfc2eb2ff",
"sha512_sri": "sha512-5esJ3UjfeZDD/DyriKAPZhHaQ55CYetibREKimT+VSc3VZ/ZRZBT3UWGBMJcz4IfpuzAfwKLoXRm5ZpU1DrcmQ=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@klapp-login-platform/native-sdk/MAL-2026-5413.json"