VYPR

npm · Malicious package advisory

Malware

dcfarguscert

GHSA-mf24-fh58-62x2

Malicious code in dcfarguscert (npm)

Details

**Severity:** Critical

**Affected versions:** `= 999.0.1`

## Source: amazon-inspector (6b0841cccc5aa4961351a4cf991d7744a1d7acc4da3824321fed50e1e7b8657d)
[email protected] registers both preinstall and postinstall lifecycle scripts that invoke src/telemetry.js. On install, telemetry.js collects host identifiers (os.hostname(), os.userInfo().username, OS release, process.platform, process.arch, Node version, CI flag) and the output of `npm ls -g --depth=0 --json` (the installer's globally installed npm package inventory), then POSTs the aggregated payload over plain HTTP to the hardcoded endpoint http://16-171-38-148.sslip.io:8080/api/install (bare IP 16.171.38.148 encoded via sslip.io). The version number 999.0.1 and the package description referencing a 'dependency test' with 'check ips' are consistent with a dependency-confusion beacon that fires unconditionally on install without any user consent or opt-out.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/015eee03d13dd119c608c3fda8034ae6e540e772/osv/malicious/npm/dcfarguscert/MAL-2026-13753.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/015eee03d13dd119c608c3fda8034ae6e540e772/osv/malicious/npm/dcfarguscert/MAL-2026-13753.json
- https://www.npmjs.com/package/dcfarguscert/v/999.0.1
- https://github.com/ossf/malicious-packages/blob/78792aee23e5c759f309a3d2e9397caf2439773e/osv/malicious/npm/dcfarguscert/MAL-2026-13753.json
- https://github.com/advisories/GHSA-mf24-fh58-62x2

Compromised versions (1)

  • = 999.0.1

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.