npm · Malicious package advisory
Malware@uol-afiliados/affiliated-config-lib
MAL-2026-16370
Malicious code in @uol-afiliados/affiliated-config-lib (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (2cd4acce57eda08c1b8716118854cad32ecfc59e35e91c03d664ac452ee6716d) @uol-afiliados/[email protected] declares a preinstall hook (`node index.js`) that shells out via `require('child_process').exec` to run `curl` against a subdomain of `hqbv58hgt1sjk7vf7ru4o0mwzn5etahz.oastify.com` (Burp Collaborator out-of-band interaction infrastructure). The subdomain is constructed with shell command substitution `$(hostname).$(whoami)`, so the installer's host name and current user name are embedded in the DNS/HTTP request and sent to the attacker-controlled collector automatically on `npm install`. The package ships no legitimate functionality — the sole install-time effect is host/user identifier exfiltration. The scoped name `@uol-afiliados/*` mimics an internal organization namespace, consistent with dependency-confusion reconnaissance.
Compromised versions (1)
- 102.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.