CRITICAL npm Malware

Malicious code in fundraiserservicepp (npm)

MAL-2026-11055

Published · Modified

Description


__

Source: amazon-inspector (6356b654b692d4c1222f3dc31dcfad683a6e193a41484d3c617c7c8d52db2313)

On npm install, the package's preinstall lifecycle executes index.js which collects os.hostname(), os.platform(), and os.arch() and POSTs them as JSON over HTTPS to the hardcoded subdomain rpke7za0zz1pwj9fz5058j0y5pbgz82wr.oastify.com — a Burp Collaborator out-of-band collector. The package provides no advertised functionality beyond this beacon and matches the dependency-confusion probe shape, with installer host identifiers leaving the machine automatically to a third-party OOB endpoint the installer did not opt into.

Source: ossf-package-analysis (cefb4588a67439c112176df4b9af71d40a1e2a12e0bf81ef200affa79e0cb0e0)

The OpenSSF Package Analysis project identified 'fundraiserservicepp' @ 1.5.0 (npm) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

Ready to move

Start Securing

Free, no credit card | First findings in minutes