npm · Malicious package advisory
Malwarecheckmate-remediation-assistant
GHSA-x239-w7m5-vrjh
Malicious code in checkmate-remediation-assistant (npm)
Details
**Severity:** Critical **Affected versions:** `= 1.0.0` ## Source: amazon-inspector (c8f55d0ebeea19e228ec6edbb1782df87539c476478d3935559fda90a458b1b4) The package's package.json declares a preinstall hook that runs index.js on npm install. index.js collects os.hostname(), os.userInfo(), the home directory, DNS server configuration, __dirname, the local package.json, and the contents of /etc/passwd and /etc/hosts, then transmits the collected data over HTTPS to a hardcoded Burp Collaborator (oastify.com) subdomain (9q0lp9mr6ek7nrnklhzkmbpuglmda4yt.oastify.com). The destination is an out-of-band interaction server not associated with any declared publisher or documented package purpose, and the exfiltration fires automatically on default install without user interaction. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/npm/checkmate-remediation-assistant/MAL-2026-17572.json)) **References:** - https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/npm/checkmate-remediation-assistant/MAL-2026-17572.json - https://www.npmjs.com/package/checkmate-remediation-assistant/v/1.0.0 - https://github.com/advisories/GHSA-x239-w7m5-vrjh
Compromised versions (1)
- = 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.