VYPR

npm · Malicious package advisory

Malware

@inpeek/odata-angular

GHSA-qfq6-5pwx-q8f5

Malicious code in @inpeek/odata-angular (npm)

Details

**Severity:** Critical

**Affected versions:** `= 99.99.102`

## Source: amazon-inspector (914508dbfa95a3d2cef5aef321a656215797f477c161a8c234e76256db6cac65)
@inpeek/[email protected] is a dependency-confusion squat on the private @inpeek scope, published to the public npm registry at an inflated version (99.99.102) to win resolution against an internal package of the same name. package.json declares scripts.postinstall as 'node./ping.js'; ping.js issues an HTTPS GET to the third-party collector https://db1b65hgnouukn3qov9gta83zgkdao9dy.oast.me/ carrying os.hostname(), os.platform(), process.version, and the package name as query parameters. index.js throws on require, so the package has no legitimate library function; the only install-time effect is the beacon to the external OAST domain. Any CI job or developer workstation whose resolver picks @inpeek/* from the public registry executes the beacon on npm install and leaks host identifiers to an attacker-controlled destination, regardless of a 'bug bounty research' framing in the description.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/28e8e300c79177f2cb1eb131ae981c3c0e639495/osv/malicious/npm/@inpeek/odata-angular/MAL-2026-17543.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/28e8e300c79177f2cb1eb131ae981c3c0e639495/osv/malicious/npm/@inpeek/odata-angular/MAL-2026-17543.json
- https://www.npmjs.com/package/@inpeek/odata-angular/v/99.99.100
- https://www.npmjs.com/package/@inpeek/odata-angular/v/99.99.101
- https://www.npmjs.com/package/@inpeek/odata-angular/v/99.99.102
- https://www.npmjs.com/package/@inpeek/odata-angular/v/99.99.99
- https://github.com/advisories/GHSA-qfq6-5pwx-q8f5

Compromised versions (1)

  • = 99.99.102

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.