Malicious code in com.db.dbk.ui-forms (npm)
The npm package com.db.dbk.ui-forms versions 99.0.0 and 99.0.1 contains malicious code that executes automatically during installation. It collects sensitive host information and environment variables potentially containing secrets, then exfiltrates this data to a hardcoded external server. The package is described as a 'dependency confusion proof of concept' but performs unauthorized data exfiltration regardless.
AI Analysis
Technical Summary
The npm package [email protected] and 99.0.1 is a version-inflated malicious package published under a scope resembling an internal namespace. Its package.json declares a preinstall script that runs index.js on npm install. This script collects host identifiers such as hostname, platform, user info, home directory, and network interfaces, as well as outputs from shell commands (uname, id, whoami). It enumerates environment variables for keys matching sensitive patterns related to credentials and tokens. The collected data is exfiltrated via HTTP(S) POST requests and DNS lookups to a hardcoded callback host at ycwyyoimdcluajepubahl0tpb7943a2z4.oast.fun. The package self-describes as a dependency confusion proof of concept but effectively performs malicious data exfiltration on installation.
Potential Impact
The malicious package can leak sensitive host information and environment variables containing secrets or credentials to an external attacker-controlled server. This can lead to credential compromise, unauthorized access, and further exploitation of affected systems where the package is installed.
Mitigation Recommendations
No official patch or remediation is indicated. Users should avoid installing com.db.dbk.ui-forms versions 99.0.0 and 99.0.1. Audit and remove this package if present. Monitor for suspicious network traffic to the indicated callback domain and investigate any potential data exposure. Consider using package integrity verification and restricting installation of untrusted or suspicious scoped packages.
Malicious code in com.db.dbk.ui-forms (npm)
Description
The npm package com.db.dbk.ui-forms versions 99.0.0 and 99.0.1 contains malicious code that executes automatically during installation. It collects sensitive host information and environment variables potentially containing secrets, then exfiltrates this data to a hardcoded external server. The package is described as a 'dependency confusion proof of concept' but performs unauthorized data exfiltration regardless.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The npm package [email protected] and 99.0.1 is a version-inflated malicious package published under a scope resembling an internal namespace. Its package.json declares a preinstall script that runs index.js on npm install. This script collects host identifiers such as hostname, platform, user info, home directory, and network interfaces, as well as outputs from shell commands (uname, id, whoami). It enumerates environment variables for keys matching sensitive patterns related to credentials and tokens. The collected data is exfiltrated via HTTP(S) POST requests and DNS lookups to a hardcoded callback host at ycwyyoimdcluajepubahl0tpb7943a2z4.oast.fun. The package self-describes as a dependency confusion proof of concept but effectively performs malicious data exfiltration on installation.
Potential Impact
The malicious package can leak sensitive host information and environment variables containing secrets or credentials to an external attacker-controlled server. This can lead to credential compromise, unauthorized access, and further exploitation of affected systems where the package is installed.
Mitigation Recommendations
No official patch or remediation is indicated. Users should avoid installing com.db.dbk.ui-forms versions 99.0.0 and 99.0.1. Audit and remove this package if present. Monitor for suspicious network traffic to the indicated callback domain and investigate any potential data exposure. Consider using package integrity verification and restricting installation of untrusted or suspicious scoped packages.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-12355
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a735741bf8831d539157759
Added to database: 08/05/2026, 15:31:13 UTC
Last enriched: 08/05/2026, 17:05:53 UTC
Last updated: 08/05/2026, 17:05:53 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.