VYPR

npm · Malicious package advisory

Malware

@inpeek/odata-angular

MAL-2026-17543

Malicious code in @inpeek/odata-angular (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (914508dbfa95a3d2cef5aef321a656215797f477c161a8c234e76256db6cac65)
@inpeek/[email protected] is a dependency-confusion squat on the private @inpeek scope, published to the public npm registry at an inflated version (99.99.102) to win resolution against an internal package of the same name. package.json declares scripts.postinstall as 'node./ping.js'; ping.js issues an HTTPS GET to the third-party collector https://db1b65hgnouukn3qov9gta83zgkdao9dy.oast.me/ carrying os.hostname(), os.platform(), process.version, and the package name as query parameters. index.js throws on require, so the package has no legitimate library function; the only install-time effect is the beacon to the external OAST domain. Any CI job or developer workstation whose resolver picks @inpeek/* from the public registry executes the beacon on npm install and leaks host identifiers to an attacker-controlled destination, regardless of a 'bug bounty research' framing in the description.

Compromised versions (4)

  • 99.99.102
  • 99.99.101
  • 99.99.100
  • 99.99.99

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.