Malicious code in poc-ch4rlygr (npm)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (341e5cb63d816ed6a8ed092f3b174e9826e10d051d8e78a53f0564b1437d0e04) On require()/import, index.js collects os.hostname(), os.arch(), __dirname, os.userInfo().username, and the full contents of process.env (serialized via Object.entries(process.env)) and issues an HTTPS GET carrying that data as a querystring to the hardcoded host zuxsp9k9vyk5y45z1n2hv0orhin9b2zr.oastify.com (a Burp Collaborator / OAST subdomain identified in-source as the receiver). Any secrets present in the installer's environment at load time (AWS_*, NPM_TOKEN, GITHUB_TOKEN, CI provider tokens, etc.) are leaked verbatim to that endpoint. package.json also declares a postinstall of `node tu-script.js`, but tu-script.js is not shipped in the tarball; the import-time module code is the operative exfiltration path.
Malicious code in poc-ch4rlygr (npm)
Description
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (341e5cb63d816ed6a8ed092f3b174e9826e10d051d8e78a53f0564b1437d0e04) On require()/import, index.js collects os.hostname(), os.arch(), __dirname, os.userInfo().username, and the full contents of process.env (serialized via Object.entries(process.env)) and issues an HTTPS GET carrying that data as a querystring to the hardcoded host zuxsp9k9vyk5y45z1n2hv0orhin9b2zr.oastify.com (a Burp Collaborator / OAST subdomain identified in-source as the receiver). Any secrets present in the installer's environment at load time (AWS_*, NPM_TOKEN, GITHUB_TOKEN, CI provider tokens, etc.) are leaked verbatim to that endpoint. package.json also declares a postinstall of `node tu-script.js`, but tu-script.js is not shipped in the tarball; the import-time module code is the operative exfiltration path.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-13454
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a7573b5bf8831d539d93baa
Added to database: 08/07/2026, 05:57:09 UTC
Last updated: 08/07/2026, 05:57:09 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.