npm · Malicious package advisory
Malware@inpeek/odata-angular
GHSA-qfq6-5pwx-q8f5
Malicious code in @inpeek/odata-angular (npm)
Details
**Severity:** Critical **Affected versions:** `= 99.99.102` ## Source: amazon-inspector (914508dbfa95a3d2cef5aef321a656215797f477c161a8c234e76256db6cac65) @inpeek/[email protected] is a dependency-confusion squat on the private @inpeek scope, published to the public npm registry at an inflated version (99.99.102) to win resolution against an internal package of the same name. package.json declares scripts.postinstall as 'node./ping.js'; ping.js issues an HTTPS GET to the third-party collector https://db1b65hgnouukn3qov9gta83zgkdao9dy.oast.me/ carrying os.hostname(), os.platform(), process.version, and the package name as query parameters. index.js throws on require, so the package has no legitimate library function; the only install-time effect is the beacon to the external OAST domain. Any CI job or developer workstation whose resolver picks @inpeek/* from the public registry executes the beacon on npm install and leaks host identifiers to an attacker-controlled destination, regardless of a 'bug bounty research' framing in the description. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/28e8e300c79177f2cb1eb131ae981c3c0e639495/osv/malicious/npm/@inpeek/odata-angular/MAL-2026-17543.json)) **References:** - https://github.com/ossf/malicious-packages/blob/28e8e300c79177f2cb1eb131ae981c3c0e639495/osv/malicious/npm/@inpeek/odata-angular/MAL-2026-17543.json - https://www.npmjs.com/package/@inpeek/odata-angular/v/99.99.100 - https://www.npmjs.com/package/@inpeek/odata-angular/v/99.99.101 - https://www.npmjs.com/package/@inpeek/odata-angular/v/99.99.102 - https://www.npmjs.com/package/@inpeek/odata-angular/v/99.99.99 - https://github.com/advisories/GHSA-qfq6-5pwx-q8f5
Compromised versions (1)
- = 99.99.102
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.