-= Per source details. Do not edit below this line.=-
On npm install, postinstall.js executes automatically and collects host identity and environment details using os.hostname(), process.cwd(), and filesystem reads, base64-encodes the data via Buffer.from(...).toString('base64'), and exfiltrates it through both DNS lookups (require('dns')) and HTTPS requests (require('https')). The dual-channel base64 exfiltration shape (DNS tunneling plus HTTPS POST) combined with collection of system identifiers is the canonical install-time data-theft fingerprint and provides direct attacker benefit: any machine running npm install for this package leaks identifying information to an external destination automatically, before the user has reviewed any package code.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-005284",
"import_time": "2026-06-10T19:23:47.938500349Z",
"modified_time": "2026-06-10T18:26:58Z",
"sha256": "0de4bc9f19feea718e091e9b0a480e9b939cdffa88109375020895c99efa489c",
"source": "amazon-inspector",
"versions": [
"99.1.1"
]
},
{
"id": "IN-MAL-2026-005285",
"import_time": "2026-06-10T19:23:48.013669047Z",
"modified_time": "2026-06-10T18:26:58Z",
"sha256": "22983c18e4a01fe9480967291bc8310bcf231043926db46d1a744c79cf1f85a6",
"source": "amazon-inspector",
"versions": [
"99.1.1"
]
},
{
"id": "IN-MAL-2026-005287",
"import_time": "2026-06-10T19:23:48.219525947Z",
"modified_time": "2026-06-10T18:27:31Z",
"sha256": "9556d538cc707208472ce3125a1a1355360126cf001957d2335ca5f4596a7e8a",
"source": "amazon-inspector",
"versions": [
"99.0.0"
]
},
{
"id": "IN-MAL-2026-005286",
"import_time": "2026-06-10T19:23:48.116490955Z",
"modified_time": "2026-06-10T18:27:31Z",
"sha256": "a31321d1ff1c689bc766a4c0c6cbe3419e4e3d9f05be465a59ce8e20d2ccab2c",
"source": "amazon-inspector",
"versions": [
"99.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
},
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"domains": [
"wybqtvzmfhssbvhokfgbwtb4j5mlyejnl.oast.fun",
"7363616e2d3965333130346234366537312e7363616e.wybqtvzmfhssbvhokfgbwtb4j5mlyejnl.oast.fun"
],
"evidence_files": [
{
"path": "postinstall.js",
"sha256": "9847baf3c44dd9ad67385f95bee607ec5f6677f179c361aa56f9a50e8341414a",
"tlsh": "763162e112f4e2205b7be0c4f96a9c569163e203710bede0f64c02651fc56b494b24f9"
}
],
"package_integrity": [
{
"filename": "browser-remedy-react-99.1.1.tgz",
"hashes": {
"sha1": "c53b97a2fd46a4f42897f6d07ebf38eb31ddba4a",
"sha512_sri": "sha512-pnjcis5DMVunnY2aloPghdvomcSj8aMPzYLnav+YAzy1iNkB0tVbY2jOmFhoRdb3TY38S22u7ht1JIQqxh3dhQ=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@access-risk/browser-remedy-react/MAL-2026-5520.json"