MAL-2026-5413

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@klapp-login-platform/native-sdk/MAL-2026-5413.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-5413
Published
2026-06-09T17:35:09Z
Modified
2026-06-09T19:01:29Z
Summary
Malicious code in @klapp-login-platform/native-sdk (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (3b3bc8633d15b44abc90074d3362fd9399f53d10a88e24264caee9d924a72bb6)

On npm install, the package's preinstall lifecycle hook runs node index.js, which collects installer-side identifiers — os.hostname(), os.userInfo().username, __dirname, process.cwd(), and the package name — and exfiltrates them through two channels. First, the JSON payload is hex-encoded into DNS labels and resolved under *.d8jbmnsqcfu78dfs8vdg34ohqhirb4pbg.oast.live, an out-of-band collector. Second, the same JSON is POSTed to a bare IP http://172.201.213.59:9090/c. Neither destination matches any documented vendor SDK endpoint. The package metadata reinforces malicious intent: the scope @klapp-login-platform resembles an internal namespace, the description is security research, and the version 99.0.2 is inflated to win dependency-confusion resolution against a private package. Installing the package immediately leaks host identity to attacker-controlled infrastructure.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-005069",
            "import_time":  "2026-06-09T17:45:52.557225152Z",
            "modified_time":  "2026-06-09T17:35:09Z",
            "sha256":  "3b3bc8633d15b44abc90074d3362fd9399f53d10a88e24264caee9d924a72bb6",
            "source":  "amazon-inspector",
            "versions":  [
                "99.0.2"
            ]
        },
        {
            "id":  "IN-MAL-2026-005070",
            "import_time":  "2026-06-09T17:45:52.604032739Z",
            "modified_time":  "2026-06-09T17:35:09Z",
            "sha256":  "4ae85072d8a51ca0d5080df8308f6bdc17112f8245cb5524e8419bb7dadf71bf",
            "source":  "amazon-inspector",
            "versions":  [
                "99.0.2"
            ]
        },
        {
            "id":  "IN-MAL-2026-005126",
            "import_time":  "2026-06-09T18:50:17.819553446Z",
            "modified_time":  "2026-06-09T17:50:20Z",
            "sha256":  "1a1c21c478fd309e16577b1d023bcc82834075d2b8f6b27ef867764c7db7c3f6",
            "source":  "amazon-inspector",
            "versions":  [
                "99.0.0"
            ]
        },
        {
            "id":  "IN-MAL-2026-005127",
            "import_time":  "2026-06-09T18:50:17.877710262Z",
            "modified_time":  "2026-06-09T17:50:20Z",
            "sha256":  "e8695fc1070f506a7aba7fc8895f25d14477e685da821196df6b59b027b65db0",
            "source":  "amazon-inspector",
            "versions":  [
                "99.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @klapp-login-platform/native-sdk

Package

Name
@klapp-login-platform/native-sdk
View open source insights on deps.dev
Purl
pkg:npm/%40klapp-login-platform%2Fnative-sdk

Affected ranges

Affected versions

99.*
99.0.0
99.0.2

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "domains":  [
        "7b2268223a227363616e2d386234653036633064633634222c2275223a22.7363616e222c2264223a222f686f6d652f7363616e2f6e6f64655f6d6f64.756c65732f406b6c6170702d6c6f67696e2d706c6174666f726d2f6e6174.d8jbmnsqcfu78dfs8vdg34ohqhirb4pbg.oast.live"
    ],
    "evidence_files":  [
        {
            "path":  "index.js",
            "sha256":  "c1db02bd41e4eb1d1b347f54a8eae90ed9e44805a5d4a34d04a85bdcb76e4c02",
            "tlsh":  "e0f00ce162b0d0fd8b708580ecd4668092b7c252b00288f4dc8d0ece0ac28e05d76ab1"
        },
        {
            "path":  "package.json",
            "sha256":  "8f45118b065eba7acc7aae228595a6e7f47dcdc796de12119a3dc64b9705d1d3",
            "tlsh":  "77d022380b31b83a076143f0acb6ac8ca0f8c31840808d1c4de740b485b17f8809d022"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "native-sdk-99.0.2.tgz",
            "hashes":  {
                "sha1":  "ffea4b3118588a5c1602e95551c5a0cdfc2eb2ff",
                "sha512_sri":  "sha512-5esJ3UjfeZDD/DyriKAPZhHaQ55CYetibREKimT+VSc3VZ/ZRZBT3UWGBMJcz4IfpuzAfwKLoXRm5ZpU1DrcmQ=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@klapp-login-platform/native-sdk/MAL-2026-5413.json"