🛡️ MAL-2026-10960 — markscan

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Malicious code in markscan (npm)

The markscan package was published to the npm registry by user 'jonothhu' (maintainer email [email protected]) as one of 19 packages in a dependency-confusion campaign targeting the 'markscan', 'akrai', and 'iphouse' namespaces, published in both unscoped and scoped (@scope/name) forms so that a misconfigured resolver installs the public lookalike instead of an intended private/internal dependency. Each package self-describes as an 'AUTHORIZED SECURITY RESEARCH CANARY' (static token PATHC-CANARY-2026, contact [email protected]), but ships an unconsented install-time beacon and provides no legitimate functionality.

The package declares a postinstall hook ("node postinstall.js") that executes automatically on npm install. The bundled postinstall.js collects host reconnaissance - the package/canary name, the static token 'PATHC-CANARY-2026', an event label, a UTC timestamp, the Node.js version, the current working directory, the platform, and os.hostname() - and exfiltrates it via HTTPS POST to a hardcoded anonymous dead-drop at https://webhook.site/129cb2ee-ba08-4b3c-989c-270dc0030350 (the same collector across all 19 packages). Request errors are swallowed.

The self-attestation of 'authorized security research' present in the package metadata is unverifiable and does not change the disposition: the package performs unconsented telemetry collection and exfiltration at install time to an anonymous collector, matching the behavior of a dependency-confusion reconnaissance beacon. Install-time behavior and the shared collector endpoint were confirmed by static analysis of a sample spanning all three namespaces and both scoped and unscoped variants.

Source: amazon-inspector

postinstall.js runs unconditionally on npm install and POSTs a JSON payload containing the installer's hostname, current working directory, platform, Node.js version, and a timestamp to a hardcoded webhook.site collector (https://webhook.site/129cb2ee-ba08-4b3c-989c-270dc0030350). The payload also carries a static token string ('PATHC-CANARY-2026'). The package's self-description as an 'authorized research canary' does not constitute installer consent — installers of markscan have not opted into the beacon, and host identifiers are transmitted to an author-controlled endpoint at install time.

Affected software

MAL-2026-10960 is recorded against 1 package.

  • markscan

Timeline and source

Published on 20 July 2026 and last revised on 4 August 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.npmjs.com (Web)
www.npmjs.com (Package)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2026-07-20
Updated 2026-08-12
Modified 2026-08-04
Fix URL N/A

Affected Packages

Software From version Fixed in
markscan

Similar Threats

Free Vulnerability Check

Is your site affected by MAL-2026-10960?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against MAL-2026-10960 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.