Skip to content

Malicious code in chapters-core (npm)

Malware Published Aug 11, 2026 to the GitHub Advisory Database • Updated Aug 11, 2026

Package

npm chapters-core (npm)

Affected versions

= 9.999.999

Patched versions

None

Description

Source: amazon-inspector (e24d8bd29ee6c23e0f394b68bbc5b580614da4479a2462c10d61387da464b992)

The package registers preinstall/postinstall lifecycle scripts that execute poc.js on npm install. poc.js collects os.hostname(), os.userInfo().username, process.cwd(), and CI/CD attribution environment variables (GITHUB_REPOSITORY, GITHUB_ACTOR, GITHUB_RUN_ID, RUNNER_NAME, npm_config_registry, AWS_REGION, JENKINS_URL, and similar) and transmits them via DNS lookups and HTTP/HTTPS POST to a hardcoded Interactsh callback subdomain awfhvaksncnsxtcdjvmnhhqbt59dzenf8.oast.fun. The package name chapters-core at version 9.999.999 is shaped as a dependency-confusion squat of an internal package name, and poc.js additionally writes a marker file samsung-depconf-poc.json into the caller's working directory. Any self-labeling of the file as research does not alter the observed behavior: install-time collection of installer host identity and internal build-environment attribution and transmission to a hardcoded, non-first-party destination.


Credit: OpenSSF (source)

References

Published to the GitHub Advisory Database Aug 11, 2026
Reviewed Aug 11, 2026
Last updated Aug 11, 2026

EPSS score

Weaknesses

Embedded Malicious Code

The product contains code that appears to be malicious in nature. Learn more on MITRE.

GHSA ID

GHSA-f5jm-mx92-p845

Source code

No known source code
Improvements are not currently accepted on this advisory because this package is malware and has no patched versions. If there is something to change, please open an issue at https://github.com/github/advisory-database/issues.