VYPR

npm · Malicious package advisory

Malware

checkmate-remediation-assistant

GHSA-x239-w7m5-vrjh

Malicious code in checkmate-remediation-assistant (npm)

Details

**Severity:** Critical

**Affected versions:** `= 1.0.0`

## Source: amazon-inspector (c8f55d0ebeea19e228ec6edbb1782df87539c476478d3935559fda90a458b1b4)
The package's package.json declares a preinstall hook that runs index.js on npm install. index.js collects os.hostname(), os.userInfo(), the home directory, DNS server configuration, __dirname, the local package.json, and the contents of /etc/passwd and /etc/hosts, then transmits the collected data over HTTPS to a hardcoded Burp Collaborator (oastify.com) subdomain (9q0lp9mr6ek7nrnklhzkmbpuglmda4yt.oastify.com). The destination is an out-of-band interaction server not associated with any declared publisher or documented package purpose, and the exfiltration fires automatically on default install without user interaction.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/npm/checkmate-remediation-assistant/MAL-2026-17572.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/npm/checkmate-remediation-assistant/MAL-2026-17572.json
- https://www.npmjs.com/package/checkmate-remediation-assistant/v/1.0.0
- https://github.com/advisories/GHSA-x239-w7m5-vrjh

Compromised versions (1)

  • = 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.