{"schema_version":"1.7.5","id":"MAL-2026-3647","published":"2026-05-09T00:00:00Z","modified":"2026-05-13T08:53:11.029588Z","summary":"Malicious code in haswons (npm)","details":"`haswons` is a typosquatting package impersonating `hasown`, the utility for checking whether an object has a direct own property. The package bundles the legitimate hasown source to appear functional while hiding a credential-theft payload in `index1.js`, executed at install time via the `postinstall` script. It is part of a campaign that also includes `briantreehttp`, `dit-envv`, and `erslove`, all sharing an identical payload and C2 infrastructure.\n\nThe payload collects hostname, platform, architecture, Node.js version, UID, current working directory, all environment variables, AWS credentials (`~/.aws/credentials`, `~/.aws/config`), npm tokens from `.npmrc` files (root, home, and working directory), Docker config (`~/.docker/config.json`), git config, `.netrc`, yarn config, npm global config, directory listings of the working directory, home, filesystem root, and `/etc`, network configuration files (`/etc/resolv.conf`, `/etc/hosts`, `/proc/net/route`), and AWS ECS/EC2 instance metadata from internal endpoints. All collected data is base64-encoded and exfiltrated via HTTPS POST to `reportviewer.click/collect/`. A secondary DNS-based exfiltration channel encodes environment variables into a subdomain and issues a request to `dns.reportviewer.click`.","affected":[{"package":{"name":"haswons","ecosystem":"npm","purl":"pkg:npm/haswons"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/haswons/MAL-2026-3647.json"}}],"database_specific":{"malicious-packages-origins":null},"credits":[{"name":"SafeDep","contact":["https://safedep.io"],"type":"FINDER"}]}