Vulnerability MAL-2026-17642
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
5 hours ago
October 07, 2026 at 04:52 AM UTC
Malicious code in personio-pipeline-projen (npm)
1.171.31
1.171.31
Summary
Malicious code in personio-pipeline-projen (npm)
Details
personio-pipeline-projen presents itself as an authorized dependency-confusion proof-of-concept; the evidence does not identify a copied public package. Its preinstall hook runs on install with node canary.js. The dependency-confusion probe encodes the installing machine's hostname and username, present CI-variable names, and root project and lifecycle identifiers in a DNS label under db2su65ptuma8gfn6ing8e7dx7wp55zit.oast.fun, and sends an HTTPS GET to hrcv3zo9m3z70yr91ssdz669c0ir6ju8.oastify.com. The npm account reaperhackbot256f published it on 2026-10-07 (UTC).
References
Impacted packages
Timeline
Published
5 hours ago
October 07, 2026 at 04:52 AM UTC
Last Modified
3 hours ago
October 07, 2026 at 07:00 AM UTC