Vulnerability MAL-2026-17437

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
4 days ago
October 01, 2026 at 02:40 AM UTC
Malicious code in @bluewin/utils (npm)
1.0.0
1.0.0

Summary

Malicious code in @bluewin/utils (npm)

Details

@bluewin/utils is a dependency-confusion package: it describes itself as a "PoC package for dependency confusion testing" and claims the @bluewin scope, so a build that resolves that scope from the public registry runs its code instead of the intended private package. Its postinstall script runs node postinstall.js on npm install, which sends an HTTPS request to https://5w2cezr3af2i0rvm72x74empvg18pzdo.oastify.com/bluewin/utils, a Burp Collaborator endpoint, disclosing the installing host's IP address and that it installed the package. It collects no further data, but unreviewed code from an outside publisher has run with the installing user's privileges. The npm account securityresearch1 published it on 2026-10-01.

Impacted packages

Timeline

Published
4 days ago
October 01, 2026 at 02:40 AM UTC
Last Modified
1 day ago
October 04, 2026 at 11:45 PM UTC