npm · Malicious package advisory
Malwareghazaly
GHSA-2j9m-4gmh-3m8p
Malicious code in ghazaly (npm)
Details
**Severity:** Critical **Affected versions:** `= 99.9.0` ## Source: amazon-inspector (d2054792481618ddf941c251fc0793ec8c1b85fe14107567b5c29cac9330d5be) package.json declares a postinstall hook that executes index.js on npm install. index.js requires os, https, and child_process, runs `whoami` via execSync, and reads os.hostname(), process.cwd(), and non-internal IPv4 addresses from os.networkInterfaces(). The collected host and identity data is sent as query-string parameters via https.get to a hardcoded Burp Collaborator subdomain (xghhv5sajm33m7krgi4n8my0mrsig84x.oastify.com). Package metadata is consistent with a dependency-confusion lure: version 99.9.0, empty author/description/keywords, and a nonsense dependency name `dependencyfsdsfdsfg` pinned to ^99.9.0. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/015eee03d13dd119c608c3fda8034ae6e540e772/osv/malicious/npm/ghazaly/MAL-2026-13755.json)) **References:** - https://github.com/ossf/malicious-packages/blob/015eee03d13dd119c608c3fda8034ae6e540e772/osv/malicious/npm/ghazaly/MAL-2026-13755.json - https://www.npmjs.com/package/ghazaly/v/99.9.0 - https://github.com/advisories/GHSA-2j9m-4gmh-3m8p
Compromised versions (1)
- = 99.9.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.