Malicious code in es6-migrator (npm)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (daeec82833ba2519ba974153de0fb545f6b5c088ed2a8145680ede73c5b0b9b8) The package's declared preinstall script runs beacon.js on npm install. The beacon unconditionally collects installer-side identity fields (hostname, OS username, current working directory, INIT_CWD, a derived context ID, runtime signature, and detected CI provider), base32-encodes them into custom X-Bug-Bounty-* request headers, and issues a plain-HTTP GET to a hardcoded bare-IP endpoint at http://45.76.249.245/beacon/QHHXFUL-YIB6g0kLLjMIDF_DFSRl2FdD/es6-migrator/1.0.1. If the HTTP callback fails or times out, beacon.js falls back to DNS out-of-band exfiltration, encoding each identity field into subdomains under seven preconfigured *.oob.asm5.net hosts and issuing A/AAAA/TXT/MX/CNAME/NS/SOA queries to tunnel the same data. The package's own metadata additionally identifies it as a dependency-confusion proof-of-concept targeting the name es6-migrator on the public registry, so any organization whose internal build resolves this name from the public registry is beaconed at install time. The bare-IP HTTP endpoint, the unrelated DNS-tunnel destination (asm5.net), the plain-HTTP transport, and the fallback design to defeat egress filtering are all inconsistent with any legitimate maintainer telemetry, and the 'authorized bug bounty' self-label in the package description is author-controlled and does not remove the install-time exfiltration.
Malicious code in es6-migrator (npm)
Description
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (daeec82833ba2519ba974153de0fb545f6b5c088ed2a8145680ede73c5b0b9b8) The package's declared preinstall script runs beacon.js on npm install. The beacon unconditionally collects installer-side identity fields (hostname, OS username, current working directory, INIT_CWD, a derived context ID, runtime signature, and detected CI provider), base32-encodes them into custom X-Bug-Bounty-* request headers, and issues a plain-HTTP GET to a hardcoded bare-IP endpoint at http://45.76.249.245/beacon/QHHXFUL-YIB6g0kLLjMIDF_DFSRl2FdD/es6-migrator/1.0.1. If the HTTP callback fails or times out, beacon.js falls back to DNS out-of-band exfiltration, encoding each identity field into subdomains under seven preconfigured *.oob.asm5.net hosts and issuing A/AAAA/TXT/MX/CNAME/NS/SOA queries to tunnel the same data. The package's own metadata additionally identifies it as a dependency-confusion proof-of-concept targeting the name es6-migrator on the public registry, so any organization whose internal build resolves this name from the public registry is beaconed at install time. The bare-IP HTTP endpoint, the unrelated DNS-tunnel destination (asm5.net), the plain-HTTP transport, and the fallback design to defeat egress filtering are all inconsistent with any legitimate maintainer telemetry, and the 'authorized bug bounty' self-label in the package description is author-controlled and does not remove the install-time exfiltration.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-15553
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a92f7d9acd9273b49e75aa8
Added to database: 08/29/2026, 15:16:41 UTC
Last updated: 08/29/2026, 15:17:15 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.