MAL-2026-6910

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/zluri-ad-connector/MAL-2026-6910.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-6910
Published
2026-07-07T06:25:49Z
Modified
2026-07-08T15:31:46.001593773Z
Summary
Malicious code in zluri-ad-connector (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (1b7a807f066f0255f7480ebd7d445043282260b464b0ef54a32a2d022c93bbf7)

The package declares a preinstall hook (node index.js) that runs automatically on npm install. index.js requires os, dns, https, querystring, and the local package.json, then harvests values from process.env matching a large sensitive-token allowlist (npm, GitHub, AWS, CI tokens, and generic secret/token/password/api_key names) along with os.hostname(), os.userInfo(), os.platform(), homedir, PATH, DNS server list, and package metadata. The collected bundle is POSTed over HTTPS to y543452sgo96xsasfdr72ms4rvxmld92.oastify.com, a Burp Collaborator subdomain used as an attacker-controlled exfiltration sink. The package name zluri-ad-connector combined with the canonical dependency-confusion version 9.9.9 indicates an intentional attempt to shadow a private Zluri internal package name so that CI resolvers pull this public malicious package.

Source: ossf-package-analysis (04e770be48b9eacfda9794e0b5865d9fb1a0232dfa90b97bfc05c75cb92dc8fe)

The OpenSSF Package Analysis project identified 'zluri-ad-connector' @ 9.9.9 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.
Database specific
{
    "malicious-packages-origins": [
        {
            "import_time": "2026-07-07T07:47:30.24702735Z",
            "sha256": "04e770be48b9eacfda9794e0b5865d9fb1a0232dfa90b97bfc05c75cb92dc8fe",
            "versions": [
                "9.9.9"
            ],
            "source": "ossf-package-analysis",
            "modified_time": "2026-07-07T06:25:49Z"
        },
        {
            "import_time": "2026-07-08T15:19:05.435826168Z",
            "id": "IN-MAL-2026-008062",
            "sha256": "1b7a807f066f0255f7480ebd7d445043282260b464b0ef54a32a2d022c93bbf7",
            "modified_time": "2026-07-08T14:33:12Z",
            "source": "amazon-inspector",
            "versions": [
                "9.9.9"
            ]
        }
    ]
}
References
Credits

Affected packages

npm / zluri-ad-connector

Package

Affected ranges

Affected versions

9.*
9.9.9

Database specific

cwes
[
    {
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code",
        "cweId": "CWE-506"
    }
]
indicators
{
    "evidence_files": [
        {
            "path": "index.js",
            "tlsh": "e84165ccd1a12a310ce60ac0685a500557aad3273a09b9d87aac43d45fcd9be12736e7",
            "sha256": "e2dfd19533d9f6f4d6fc7418770eef772df697a86d6edc3d0b59f51eccacd8fc"
        },
        {
            "path": "package.json",
            "tlsh": "2ae0d820ea716d2316d70355482660856261dfe70e583d0d378b153c8fae2b7aafa29f",
            "sha256": "b2b75d8d87182c37970229a57a743af44553b4f0534ec3f1d512d7d98f2c941f"
        }
    ],
    "package_integrity": [
        {
            "filename": "zluri-ad-connector-9.9.9.tgz",
            "hashes": {
                "sha512_sri": "sha512-M2WYzwRGHAgXJ4b4S1Otwt8q9GttpLcaIA/sjL3tIlK1r/px7szzfoOT2MZm1BGenY74mx+DrWh5x3lXB5NmsQ==",
                "sha1": "c295986cddf95a26e5fe8329b3564a4c8a541ca7"
            }
        }
    ]
}
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/zluri-ad-connector/MAL-2026-6910.json"