Malicious code in @broadpeak/smartlib-ad (npm)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (45df33d93645560085a7efe94308b0e3d846f30c829f2d2804bcdb1245626289) package.json declares `preinstall: node index.js`, which fires automatically on `npm install`. index.js loads child_process/os/https, runs `whoami` and `id`, collects host identifiers (os.hostname, os.platform, os.arch, os.homedir, os.userInfo username/uid/gid/shell, os.type, os.release, process.cwd), and POSTs the collected JSON to a hardcoded Burp Collaborator (OAST) subdomain at https://3quc59n15cfcretszaygwfm9v01rphd6.oastify.com/detox56. The package ships no functional code beyond this beacon, has empty description/author, and is published under the `@broadpeak` scope — consistent with dependency-confusion reconnaissance impersonating an internal Broadpeak package. Installing this package leaks installer host/user identifiers to an attacker-controlled out-of-band endpoint and confirms code execution inside the target's build environment for follow-up targeting.
AI Analysis
Technical Summary
The malicious npm package @broadpeak/[email protected] declares a preinstall script that runs automatically on npm install. This script executes system commands (whoami, id), collects host identifiers such as hostname, platform, architecture, user info, and current working directory, then sends this data as JSON to a hardcoded Burp Collaborator OAST endpoint controlled by an attacker. The package lacks functional code and legitimate metadata, consistent with reconnaissance for dependency confusion attacks. This confirms arbitrary code execution during installation and leaks sensitive environment information to the attacker.
Potential Impact
Installation of this package leads to unauthorized execution of code on the installer's system, resulting in leakage of sensitive host and user environment information to an attacker-controlled external endpoint. This compromises confidentiality of the build environment and confirms the ability of the attacker to execute code within that environment, potentially enabling further targeted attacks.
Mitigation Recommendations
No official patch or remediation is currently available. Users should avoid installing the @broadpeak/smartlib-ad package version 24.1.10. Verify package authenticity before installation, especially for packages scoped to internal or private namespaces. Monitor for and remove any instances of this package in build environments. Patch status is not yet confirmed — check the vendor advisory or trusted sources for updates.
Malicious code in @broadpeak/smartlib-ad (npm)
Description
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (45df33d93645560085a7efe94308b0e3d846f30c829f2d2804bcdb1245626289) package.json declares `preinstall: node index.js`, which fires automatically on `npm install`. index.js loads child_process/os/https, runs `whoami` and `id`, collects host identifiers (os.hostname, os.platform, os.arch, os.homedir, os.userInfo username/uid/gid/shell, os.type, os.release, process.cwd), and POSTs the collected JSON to a hardcoded Burp Collaborator (OAST) subdomain at https://3quc59n15cfcretszaygwfm9v01rphd6.oastify.com/detox56. The package ships no functional code beyond this beacon, has empty description/author, and is published under the `@broadpeak` scope — consistent with dependency-confusion reconnaissance impersonating an internal Broadpeak package. Installing this package leaks installer host/user identifiers to an attacker-controlled out-of-band endpoint and confirms code execution inside the target's build environment for follow-up targeting.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The malicious npm package @broadpeak/[email protected] declares a preinstall script that runs automatically on npm install. This script executes system commands (whoami, id), collects host identifiers such as hostname, platform, architecture, user info, and current working directory, then sends this data as JSON to a hardcoded Burp Collaborator OAST endpoint controlled by an attacker. The package lacks functional code and legitimate metadata, consistent with reconnaissance for dependency confusion attacks. This confirms arbitrary code execution during installation and leaks sensitive environment information to the attacker.
Potential Impact
Installation of this package leads to unauthorized execution of code on the installer's system, resulting in leakage of sensitive host and user environment information to an attacker-controlled external endpoint. This compromises confidentiality of the build environment and confirms the ability of the attacker to execute code within that environment, potentially enabling further targeted attacks.
Mitigation Recommendations
No official patch or remediation is currently available. Users should avoid installing the @broadpeak/smartlib-ad package version 24.1.10. Verify package authenticity before installation, especially for packages scoped to internal or private namespaces. Monitor for and remove any instances of this package in build environments. Patch status is not yet confirmed — check the vendor advisory or trusted sources for updates.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-10178
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a520ea968715ace438f47be
Added to database: 07/11/2026, 09:36:41 UTC
Last enriched: 07/11/2026, 09:45:50 UTC
Last updated: 07/30/2026, 19:08:40 UTC
Views: 25
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.