VYPR

npm · Malicious package advisory

Malware

@uol-afiliados/affiliated-config-lib

GHSA-mh6g-473c-fvhx

Malicious code in @uol-afiliados/affiliated-config-lib (npm)

Details

**Severity:** Critical

**Affected versions:** `= 102.0.0`

## Source: amazon-inspector (2cd4acce57eda08c1b8716118854cad32ecfc59e35e91c03d664ac452ee6716d)
@uol-afiliados/[email protected] declares a preinstall hook (`node index.js`) that shells out via `require('child_process').exec` to run `curl` against a subdomain of `hqbv58hgt1sjk7vf7ru4o0mwzn5etahz.oastify.com` (Burp Collaborator out-of-band interaction infrastructure). The subdomain is constructed with shell command substitution `$(hostname).$(whoami)`, so the installer's host name and current user name are embedded in the DNS/HTTP request and sent to the attacker-controlled collector automatically on `npm install`. The package ships no legitimate functionality — the sole install-time effect is host/user identifier exfiltration. The scoped name `@uol-afiliados/*` mimics an internal organization namespace, consistent with dependency-confusion reconnaissance.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/7ae960133637ba13697c4fbec21ce9558bc7ce7b/osv/malicious/npm/@uol-afiliados/affiliated-config-lib/MAL-2026-16370.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/7ae960133637ba13697c4fbec21ce9558bc7ce7b/osv/malicious/npm/@uol-afiliados/affiliated-config-lib/MAL-2026-16370.json
- https://www.npmjs.com/package/@uol-afiliados/affiliated-config-lib/v/102.0.0
- https://github.com/advisories/GHSA-mh6g-473c-fvhx

Compromised versions (1)

  • = 102.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.