npm · Malicious package advisory
Malware@pelmnaads/naads-common-logger
MAL-2026-3748
Malicious code in @pelmnaads/naads-common-logger (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (68990dfacdc750bf464d646aca4855c2dd23bbefcadef1d9638e2d663a23fc57) The package is published to the public npm registry under `@pelmnaads/naads-common-logger` with version `19999.0.1` — the canonical dependency-confusion pattern, where an abnormally high version is used to make npm's resolver prefer this public package over a private internal package of the same name. On `npm install`, a `preinstall` lifecycle script (preinstall.js:5-9) makes an HTTPS GET to `h5nvwrz2815ubw84cpkwhezm5db9z1nq.b.mburpcollab.com` with query parameters `package=<npm_package_name>&hostname=<os.hostname()>`, transmitting the installer's hostname off-host to a Burp Collaborator out-of-band interaction endpoint. The README states this is an authorized security test, but the code path and effect on an unsuspecting installer are identical to a hostile dependency-confusion attack: build hosts silently disclose their identity to a third-party domain during `npm install`, with no opt-in. Any build system that resolves this package (e.g., an internal Pelmorex pipeline expecting the private `@pelmnaads/naads-common-logger`) would leak hostname data.
Compromised versions (1)
- 19999.0.1
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.