OpenSSF/OSV advisory MAL-2026-17432 confirms this npm version as malicious. brioche-apl-dev-env is a dependency-confusion package: it takes a name that looks like an internal project, uses an inflated version (100.0.0) so it outranks private-registry versions, and runs `node setup.js || true` as a preinstall script on npm install. setup.js sends the hostname, username, working directory, OS, architecture, Node.js version and configured npm registry, with a per-package tracking token, in an...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in brioche-apl-dev-env (npm)
Details
brioche-apl-dev-env is a dependency-confusion package: it takes a name that looks like an internal project, uses an inflated version (100.0.0) so it outranks private-registry versions, and runs `node setup.js || true` as a preinstall script on npm install. setup.js sends the hostname, username, working directory, OS, architecture, Node.js version and configured npm registry, with a per-package tracking token, in an HTTPS POST to `https://s85r5k14qk.execute-api.us-east-1.amazonaws.com/prod/hook`. The npm account amel10 published brioche-apl-dev-env and 9 similar packages within two minutes on 2026-09-30, all with the same setup.js.
---
## Source: amazon-inspector (637c99e6cd2bd8e143f01f5f522a7497375a24072fca131057cfd40ae0bb0d3e) The package declares a `preinstall` script that runs `setup.js` during `npm install`. That script collects installer host identifiers (hostname, OS username, current working directory, platform/arch, Node.js version, configured npm registry) together with a static per-package token, serializes them as JSON, and POSTs them to a hardcoded endpoint at https://s85r5k14qk.execute-api.us-east-1.amazonaws.com/prod/hook. The package is presented as a small utility (vowel-counting) but its only install-time effect is this outbound beacon to an author-controlled AWS API Gateway URL. The version number (100.0.0) and package naming are consistent with a dependency-confusion lure targeting an internal `brioche-apl-*` namespace, and the transmitted fields (internal hostname, username, cwd, configured registry) are exactly the reconnaissance data used to identify successfully hijacked internal builds.