VYPR

npm · Malicious package advisory

Malware

@dgn-src-click-to-pay-org/srcdcfreleasecert

GHSA-hfmm-qxg4-g578

Malicious code in @dgn-src-click-to-pay-org/srcdcfreleasecert (npm)

Details

**Severity:** Critical

**Affected versions:** `= 999.0.1`

## Source: amazon-inspector (6c203676b4cd54080189fef8d6740d09a1667f2ba0d939936ee46bd6dda4e15d)
The package's postinstall hook (scripts/check-env.js) executes on npm install and POSTs the package name/version along with the host's platform, architecture, and Node.js version to a hardcoded bare-IP endpoint at http://16-171-38-148.sslip.io:8080/api/install over plain HTTP. The package is published at version 999.0.1 — a sentinel value chosen to outrank legitimate internal versions during resolution — under a scoped organization name evoking a payments vendor (Discover/SRC click-to-pay), while the module body contains only trivial PAN/Luhn helpers. This is the canonical dependency-confusion reconnaissance shape: the squatted scope resolves inside a target build system and the postinstall beacon reports back which internal environments were successfully hijacked, enabling attacker follow-up against those hosts.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/015eee03d13dd119c608c3fda8034ae6e540e772/osv/malicious/npm/@dgn-src-click-to-pay-org/srcdcfreleasecert/MAL-2026-13744.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/015eee03d13dd119c608c3fda8034ae6e540e772/osv/malicious/npm/@dgn-src-click-to-pay-org/srcdcfreleasecert/MAL-2026-13744.json
- https://www.npmjs.com/package/@dgn-src-click-to-pay-org/srcdcfreleasecert/v/999.0.1
- https://github.com/ossf/malicious-packages/blob/fab7a1742d58ad342ae3b3e018b6b545cdb9c4f8/osv/malicious/npm/@dgn-src-click-to-pay-org/srcdcfreleasecert/MAL-2026-13744.json
- https://www.npmjs.com/package/@dgn-src-click-to-pay-org/srcdcfreleasecert/v/374.0.0
- https://github.com/advisories/GHSA-hfmm-qxg4-g578

Compromised versions (1)

  • = 999.0.1

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.