OpenSSF/OSV advisory MAL-2026-4639 confirms this npm version as malicious. On require/load, index.js unconditionally collects host identifiers (hostname, username, platform, arch, cwd, pid) and sends them as URL query parameters via HTTPS GET to a hardcoded Burp Collaborator-style domain `vwfmeddcdgidvdwpkigkg0l8us5vf3wtx.oast.fun`. The package ships no advertised functionality — its only behavior on load is the beacon. package.json has empty author/description fields and declares an...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in pg-expense-example (npm)
Details
On require/load, index.js unconditionally collects host identifiers (hostname, username, platform, arch, cwd, pid) and sends them as URL query parameters via HTTPS GET to a hardcoded Burp Collaborator-style domain `vwfmeddcdgidvdwpkigkg0l8us5vf3wtx.oast.fun`. The package ships no advertised functionality — its only behavior on load is the beacon. package.json has empty author/description fields and declares an unused `chalk` dependency. A code comment in Azerbaijani (`sənin domenin` = 'your domain') is consistent with an attacker-controlled callback host, indicating PoC/reconnaissance malware rather than legitimate software.
Decision reason
OpenSSF Malicious Packages via OSV confirms pg-expense-example@1.0.0 as malicious (MAL-2026-4639): Malicious code in pg-expense-example (npm)