OpenSSF/OSV advisory MAL-2026-11065 confirms this npm version as malicious. Package name typosquats swiper/swiper-angular at implausible version 5.9999.1. The preinstall.js script runs at install time and collects installer host identity and network context — os.hostname(), os.userInfo() username, current working directory, package name, git remote domain, /etc/resolv.conf search domain, /etc/hosts and /etc/hostname content grepped for 'tbi|beez|tbibank', egress IP via `ip route get...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in swiper_angular (npm)
Details
Package name typosquats swiper/swiper-angular at implausible version 5.9999.1. The preinstall.js script runs at install time and collects installer host identity and network context — os.hostname(), os.userInfo() username, current working directory, package name, git remote domain, /etc/resolv.conf search domain, /etc/hosts and /etc/hostname content grepped for 'tbi|beez|tbibank', egress IP via `ip route get 1.1.1.1` and `curl -s ifconfig.me`, and environment variable names filtered against the same organization tokens. The collected fields are concatenated into a query string and sent via https.get to the hardcoded Interactsh subdomain rmknhtfmmidejheotogony3qpqrk75wdz.oast.fun/cb2. Behavior fires automatically on npm install with no consent prompt and targets a specific organization (tbibank) regardless of the self-applied 'security research' label.
## Source: ossf-package-analysis (474db4780bfc49ff2146966bdd508c123baf4d39c636e27aaba1996a0016d8f6) The OpenSSF Package Analysis project identified 'swiper_angular' @ 5.9999.0 (npm) as malicious.
It is considered malicious because:
- The package communicates with a domain associated with malicious activity.
Decision reason
OpenSSF Malicious Packages via OSV confirms swiper_angular@5.9999.1 as malicious (MAL-2026-11065): Malicious code in swiper_angular (npm)