VYPR

npm · Malicious package advisory

Malware

ghazaly

GHSA-2j9m-4gmh-3m8p

Malicious code in ghazaly (npm)

Details

**Severity:** Critical

**Affected versions:** `= 99.9.0`

## Source: amazon-inspector (d2054792481618ddf941c251fc0793ec8c1b85fe14107567b5c29cac9330d5be)
package.json declares a postinstall hook that executes index.js on npm install. index.js requires os, https, and child_process, runs `whoami` via execSync, and reads os.hostname(), process.cwd(), and non-internal IPv4 addresses from os.networkInterfaces(). The collected host and identity data is sent as query-string parameters via https.get to a hardcoded Burp Collaborator subdomain (xghhv5sajm33m7krgi4n8my0mrsig84x.oastify.com). Package metadata is consistent with a dependency-confusion lure: version 99.9.0, empty author/description/keywords, and a nonsense dependency name `dependencyfsdsfdsfg` pinned to ^99.9.0.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/015eee03d13dd119c608c3fda8034ae6e540e772/osv/malicious/npm/ghazaly/MAL-2026-13755.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/015eee03d13dd119c608c3fda8034ae6e540e772/osv/malicious/npm/ghazaly/MAL-2026-13755.json
- https://www.npmjs.com/package/ghazaly/v/99.9.0
- https://github.com/advisories/GHSA-2j9m-4gmh-3m8p

Compromised versions (1)

  • = 99.9.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.