Malicious code in application_base (npm)
The npm package application_base version 9999.0.0 contains malicious code in its preinstall lifecycle hook. This code collects system and environment information including hostname, username, current working directory, npm registry, and CI repository environment variables. It then sends this data via an HTTP GET request to an external IP address, which is not a legitimate telemetry endpoint. This behavior is indicative of a dependency confusion reconnaissance attempt, allowing attackers to identify if an internal package name resolves to their public registry entry and gather information to target organizations for further attacks.
AI Analysis
Technical Summary
The npm package [email protected] executes a script during its preinstall lifecycle hook that collects sensitive environment details such as os.hostname(), os.userInfo().username, process.cwd(), the configured npm registry, and various CI repository environment variables (e.g., GITHUB_REPOSITORY, CI_PROJECT_PATH). It sends these details in an HTTP GET request to a non-first-party IP address (http://75.119.137.232:31337/depconfuse). This behavior serves as a reconnaissance beacon for dependency confusion attacks, signaling to attackers whether an internal package name resolves to their public registry entry within a target's build environment, thereby facilitating targeted internal-package hijacking.
Potential Impact
The malicious code leaks sensitive environment and build information to an attacker-controlled server. This information can be used to confirm successful dependency confusion attacks and to tailor follow-on attacks targeting internal packages within the victim's build environment. While no direct exploitation or code execution beyond data exfiltration is described, the reconnaissance facilitates potentially serious supply chain attacks.
Mitigation Recommendations
No official patch or remediation is currently documented for [email protected]. Users should avoid installing this specific version due to its malicious behavior. Monitor package sources carefully and prefer verified, trusted packages. Check vendor advisories or npm security notices for updates or removal of this malicious package. Since this is a malicious package published to a public registry, removing or blocking this version from internal use is recommended.
Malicious code in application_base (npm)
Description
The npm package application_base version 9999.0.0 contains malicious code in its preinstall lifecycle hook. This code collects system and environment information including hostname, username, current working directory, npm registry, and CI repository environment variables. It then sends this data via an HTTP GET request to an external IP address, which is not a legitimate telemetry endpoint. This behavior is indicative of a dependency confusion reconnaissance attempt, allowing attackers to identify if an internal package name resolves to their public registry entry and gather information to target organizations for further attacks.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The npm package [email protected] executes a script during its preinstall lifecycle hook that collects sensitive environment details such as os.hostname(), os.userInfo().username, process.cwd(), the configured npm registry, and various CI repository environment variables (e.g., GITHUB_REPOSITORY, CI_PROJECT_PATH). It sends these details in an HTTP GET request to a non-first-party IP address (http://75.119.137.232:31337/depconfuse). This behavior serves as a reconnaissance beacon for dependency confusion attacks, signaling to attackers whether an internal package name resolves to their public registry entry within a target's build environment, thereby facilitating targeted internal-package hijacking.
Potential Impact
The malicious code leaks sensitive environment and build information to an attacker-controlled server. This information can be used to confirm successful dependency confusion attacks and to tailor follow-on attacks targeting internal packages within the victim's build environment. While no direct exploitation or code execution beyond data exfiltration is described, the reconnaissance facilitates potentially serious supply chain attacks.
Mitigation Recommendations
No official patch or remediation is currently documented for [email protected]. Users should avoid installing this specific version due to its malicious behavior. Monitor package sources carefully and prefer verified, trusted packages. Check vendor advisories or npm security notices for updates or removal of this malicious package. Since this is a malicious package published to a public registry, removing or blocking this version from internal use is recommended.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-12511
- Osv Schema Version
- 1.7.4
- Ecosystems
- ["npm"]
Threat ID: 6a73573fbf8831d5391536ba
Added to database: 08/05/2026, 15:31:11 UTC
Last enriched: 08/05/2026, 16:55:17 UTC
Last updated: 09/11/2026, 10:41:45 UTC
Views: 17
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.