npm · Malicious package advisory
Malwarepaypal-business-sdk
GHSA-28xq-h9vx-4xqx
Malicious code in paypal-business-sdk (npm)
Details
**Severity:** Critical **Affected versions:** `= 9.4.3` ## Source: amazon-inspector (556bfd93652f806523495944dc8a441624c9a2dae4f76eadeefa9650f57091a1) The package's npm preinstall lifecycle script collects the installer's OS username, hostname, current working directory, and walks up to 15 parent directories to read enclosing package.json files (capturing the victim project's name, author, and version). The collected metadata is hex-encoded, chunked into DNS subdomain labels, and exfiltrated via dns.lookup queries under the hardcoded nameserver o.jgl.red (observed label da5u87oh92rc72pp1dngqfc6hp8gwshm6.o.jgl.red). The package name impersonates a PayPal SDK, consistent with a dependency-confusion reconnaissance beacon that fires automatically on npm install. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/72e5d8219b286d7332c4ad2364b87986138cf34c/osv/malicious/npm/paypal-business-sdk/MAL-2026-14435.json)) **References:** - https://github.com/ossf/malicious-packages/blob/72e5d8219b286d7332c4ad2364b87986138cf34c/osv/malicious/npm/paypal-business-sdk/MAL-2026-14435.json - https://www.npmjs.com/package/paypal-business-sdk/v/9.4.3 - https://github.com/advisories/GHSA-28xq-h9vx-4xqx
Compromised versions (1)
- = 9.4.3
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.