Threats Tagged 'mal-2026-11147'
View all threats tagged with 'mal-2026-11147'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'mal-2026-11147'
Click on any threat for detailed analysis and mitigation recommendations
Malicious code in simple-probe-utils (npm) 0 --- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (0457a026ab28fbb641d11e4e9ac9d60d026fd77210972f72e6ac931b4b06c59c) On npm install, postinstall.js executes shell commands that query cloud instance metadata services (AWS IMDS at 169.254.169.254, plus Tencent, Aliyun, GCP, and Azure endpoints) and extracts the AWS IAM role's temporary security credentials. The captured IAM credentials, hostname, and username are appended as query parameters to an HTTP request to the hardcoded out-of-band host pzs5w7ntzhsnepwk564lyfdci3oucl0a.oastify.com (a Burp Collaborator-style domain). The package.json describes the module as a lightweight string formatting helper; the shipped code contains only the credential-harvesting postinstall, with no string-utility functionality present. Join the discussion | GCVE Database | 07/28/2026, 13:43:24 UTC Added: 08/05/2026, 15:30:55 UTC |
Showing 1 to 1 of 1 result