VYPR

npm · Malicious package advisory

Malware

@car-loans/feature-toggles-module

GHSA-vcr4-g6v2-wxvh

Malicious code in @car-loans/feature-toggles-module (npm)

Details

**Severity:** Critical

**Affected versions:** `> 0`

Part of a dependency confusion attack campaign targeting the `@car-loans`, `@fb-deposit`, and `@debit-ib` npm scopes. The attacker (npm user **pik-libs**) published 25 scoped packages at the inflated version `99.99.99`, which resolves ahead of any private registry version via npm's default version resolution, silently hijacking installs of internal packages. The campaign shares infrastructure (`https://oob.moika.tech`) and an identical postinstall payload with a concurrent campaign by npm user **mr.4nd3r50n**.

On installation, the `postinstall` hook executes `scripts/postinstall.js`. The script waits 3 seconds (sandbox evasion), then downloads an OS-specific second-stage JavaScript payload from `https://oob.moika.tech/payload/{mac|win|linux}.js`, writes it to a temporary file in the system temp directory, and spawns it as a detached Node.js process that continues running after npm exits. The payload exfiltrates the full `process.env` (environment variables including secrets, tokens, and credentials), along with hostname, username, platform, architecture, and working directory, to the C2 endpoint `https://oob.moika.tech/report`. If the second-stage download fails, a fallback beacon containing the same system details is sent to the same endpoint.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/6911f74354c2db7446264ece95ffab0b47b56f4a/osv/malicious/npm/@car-loans/feature-toggles-module/MAL-2026-4869.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/6911f74354c2db7446264ece95ffab0b47b56f4a/osv/malicious/npm/@car-loans/feature-toggles-module/MAL-2026-4869.json
- https://safedep.io/oob-moika-tech-dependency-confusion-campaign
- https://github.com/advisories/GHSA-vcr4-g6v2-wxvh

Compromised versions (1)

  • > 0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.