Malicious code in csv-parser-helper (npm)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (90b87a86eaa4be59def7e48ce9b004266b8c4815a71c84fd1d3df879c702c1ca) The package is advertised as a CSV parser but ships a postinstall.js that runs on `npm install` and performs installer-side reconnaissance and exfiltration. It shell-collects hostname, current user, working directory, `uname -a`, container indicators, process tree, and network information; probes AWS and Tencent instance metadata services at 169.254.169.254 and metadata.tencentyun.com; and dumps the full process environment while filtering out only npm noise (retaining any token/secret-shaped variables such as GITHUB_TOKEN, cloud provider keys, and CI credentials). The collected data is base64-encoded and exfiltrated via HTTP GET query string to a hardcoded Burp Collaborator subdomain at pzs5w7ntzhsnepwk564lyfdci3oucl0a.oastify.com. The package's stated CSV-parsing purpose is a cover story — index.js is unrelated code and no CSV functionality is present.
Malicious code in csv-parser-helper (npm)
Description
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (90b87a86eaa4be59def7e48ce9b004266b8c4815a71c84fd1d3df879c702c1ca) The package is advertised as a CSV parser but ships a postinstall.js that runs on `npm install` and performs installer-side reconnaissance and exfiltration. It shell-collects hostname, current user, working directory, `uname -a`, container indicators, process tree, and network information; probes AWS and Tencent instance metadata services at 169.254.169.254 and metadata.tencentyun.com; and dumps the full process environment while filtering out only npm noise (retaining any token/secret-shaped variables such as GITHUB_TOKEN, cloud provider keys, and CI credentials). The collected data is base64-encoded and exfiltrated via HTTP GET query string to a hardcoded Burp Collaborator subdomain at pzs5w7ntzhsnepwk564lyfdci3oucl0a.oastify.com. The package's stated CSV-parsing purpose is a cover story — index.js is unrelated code and no CSV functionality is present.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-12360
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a735747bf8831d53915a0f9
Added to database: 08/05/2026, 15:31:19 UTC
Last updated: 08/05/2026, 15:31:19 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.