npm · Malicious package advisory
Malware@demica/core
GHSA-qjx6-cvh3-44x4
Malicious code in @demica/core (npm)
Details
**Severity:** Critical **Affected versions:** `> 0` Dep-confusion squat of internal @demica/core at sentinel high version 99.99.100 + auto-exec postinstall (canary.js) beaconing to RAW IP 157.230.17.236:80/dc. Sentinel-high-version + auto-exec beacon = MALICIOUS per operator policy (c913); "authorized benign canary" framing does NOT downgrade, raw-IP dest matches masterkrweb. 6-pkg @demica canary campaign.## Source: amazon-inspector (3abd78892d57868223d66ae70f269e5088d5801f5beaa41418146172a3e5e338) Package self-describes as a dependency-confusion canary targeting the @demica scope and ships a postinstall hook that fires automatically on `npm install`. `package.json` declares `scripts.postinstall: node canary.js postinstall`, and canary.js lines 18-22 issue an HTTP GET to the bare IP 157.230.17.236 on port 80 at path `/dc?...` with the package name, version, a nonce, and the lifecycle phase. Any machine that resolves @demica/[email protected] from the public registry — typically because an internal build accidentally pulled the public squat instead of the private @demica/core — silently announces itself to the operator of 157.230.17.236, disclosing the installer's egress IP, the presence of the @demica internal namespace in the build, and confirmation that the dependency-confusion attack succeeded. The beacon body is metadata-only (no env/filesystem/credential reads), but the install-time outbound HTTP to a hardcoded attacker-controlled bare IP, fired without consent on default install, is the canonical dependency-confusion exploitation primitive and gives the publisher exactly the reconnaissance signal needed to identify and escalate against vulnerable internal build pipelines. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/c611ebbba1ad58f1e65013eb1e39375d6eb21ea2/osv/malicious/npm/@demica/core/MAL-2026-5349.json)) **References:** - https://app.safedep.io/community/malysis/01KTMB3NABY1QVRDFBY2QWYP46 - https://github.com/ossf/malicious-packages/blob/c611ebbba1ad58f1e65013eb1e39375d6eb21ea2/osv/malicious/npm/@demica/core/MAL-2026-5349.json - https://www.npmjs.com/package/@demica/core/v/99.99.100 - https://www.npmjs.com/package/@demica/core/v/99.99.99 - https://github.com/advisories/GHSA-qjx6-cvh3-44x4
Compromised versions (1)
- > 0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.