🛡️ MAL-2026-6997 — goofy-sdk

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Malicious code in goofy-sdk (npm)

Source: amazon-inspector

[email protected] is a dependency-confusion squat: the version is inflated to 9999.0.0 to shadow an internal package of the same name in build systems that resolve unscoped names against the public npm registry. On install, the package's preinstall hook executes callback.js, which reads os.hostname(), os.userInfo().username, process.platform, and process.cwd() and transmits them out-of-band to *.oast.fun (Interactsh OAST callback infrastructure) via a DNS subdomain-encoded lookup and an HTTPS POST. Any build system that mis-resolves the internal name to this public package will silently leak internal host identity to a third-party callback service. Self-declared bug-bounty/research framing does not change the installer-side impact — the harm (unconsented host-identity beacon on install) is the same regardless of motive.

Affected software

MAL-2026-6997 is recorded against 1 package.

  • goofy-sdk

Timeline and source

Published on 8 July 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.npmjs.com (Package)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2026-07-08
Updated 2026-08-12
Modified 2026-07-08
Fix URL N/A

Affected Packages

Software From version Fixed in
goofy-sdk

Free Vulnerability Check

Is your site affected by MAL-2026-6997?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against MAL-2026-6997 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.