MAL-2026-5414

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@klapp-login-platform/oidc/MAL-2026-5414.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-5414
Published
2026-06-09T17:35:15Z
Modified
2026-06-09T19:01:29Z
Summary
Malicious code in @klapp-login-platform/oidc (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (6c2b86b9675d4d22e101f4f10f521cc36069ecebd1680d4c3ecfa0c04e8169da)

On npm install, the package executes node index.js via its preinstall hook. index.js collects the installer's hostname (os.hostname()), username (os.userInfo().username), package directory (__dirname), and current working directory (process.cwd()), serializes them to JSON, hex-encodes the payload, and exfiltrates it through two channels: (1) a DNS resolution of a subdomain under d8jbmnsqcfu78dfs8vdg34ohqhirb4pbg.oast.live (interactsh-style out-of-band exfiltration), and (2) an HTTP POST to the bare IP 172.201.213.59:9090/c. The package ships no documented functionality matching its @klapp-login-platform/oidc name; the description is 'security research'. The high version number (99.0.2) under an org-style scope on the public registry is consistent with a dependency-confusion attack designed to pre-empt resolution of an internal private package of the same name, and the beaconing payload provides the attacker with confirmation of which organizations have resolved the public version.

Database specific
{
    "malicious-packages-origins":  [
        {
            "id":  "IN-MAL-2026-005072",
            "import_time":  "2026-06-09T17:45:52.783008124Z",
            "modified_time":  "2026-06-09T17:35:15Z",
            "sha256":  "11ee7c03075e594b6e2853b480a25dcb21e349e929c5a0e9ce2d4a3893eb7931",
            "source":  "amazon-inspector",
            "versions":  [
                "99.0.2"
            ]
        },
        {
            "id":  "IN-MAL-2026-005071",
            "import_time":  "2026-06-09T17:45:52.658354509Z",
            "modified_time":  "2026-06-09T17:35:15Z",
            "sha256":  "6c2b86b9675d4d22e101f4f10f521cc36069ecebd1680d4c3ecfa0c04e8169da",
            "source":  "amazon-inspector",
            "versions":  [
                "99.0.2"
            ]
        },
        {
            "id":  "IN-MAL-2026-005125",
            "import_time":  "2026-06-09T18:50:17.734880471Z",
            "modified_time":  "2026-06-09T17:49:43Z",
            "sha256":  "d345e380cc2c86b2c8cb5578e657199a73d9627e6839459ada7b6e5eaba4cc24",
            "source":  "amazon-inspector",
            "versions":  [
                "99.0.0"
            ]
        },
        {
            "id":  "IN-MAL-2026-005124",
            "import_time":  "2026-06-09T18:50:17.541135555Z",
            "modified_time":  "2026-06-09T17:49:43Z",
            "sha256":  "fc2fae7737666daf215586b5c271c5266980f39ab734b7b043558203ce2f1080",
            "source":  "amazon-inspector",
            "versions":  [
                "99.0.0"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / @klapp-login-platform/oidc

Package

Name
@klapp-login-platform/oidc
View open source insights on deps.dev
Purl
pkg:npm/%40klapp-login-platform%2Foidc

Affected ranges

Affected versions

99.*
99.0.0
99.0.2

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    },
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
indicators
{
    "domains":  [
        "7b2268223a227363616e2d386630663633616136323435222c2275223a22.7363616e222c2264223a222f686f6d652f7363616e2f6e6f64655f6d6f64.756c65732f406b6c6170702d6c6f67696e2d706c6174666f726d2f6f6964.d8jbmnsqcfu78dfs8vdg34ohqhirb4pbg.oast.live"
    ],
    "evidence_files":  [
        {
            "path":  "index.js",
            "sha256":  "db7379cc98c6fb55ceffe6b6d569db695b575c82d63857c6170366a1bc959c96",
            "tlsh":  "f1f00ce162b0d0f98b708980ecc4668053b7c252b00288e4dc0d0ecf0ac24e05d76aa1"
        },
        {
            "path":  "package.json",
            "sha256":  "a8451d05deeb1c1b6ebd492936e39ada28f20f877568ddf00742b06a23339099",
            "tlsh":  "4fc022380931b836076146f0a8b6ac4c61f8c25400808d0c4ee380b086b17e8809d002"
        }
    ],
    "package_integrity":  [
        {
            "filename":  "oidc-99.0.2.tgz",
            "hashes":  {
                "sha1":  "85e2ef3c81d76a31daf1f93b0968e208a3cd8f24",
                "sha512_sri":  "sha512-LVt3lU0rfSxuLpIp2caRXan7Js9Bv79dtTsOnt+XCVyLZxt12oO4D9XVPTIegbaFoz4RmaPuROcmoB10ybVNRQ=="
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@klapp-login-platform/oidc/MAL-2026-5414.json"