MAL-2026-12334
Malicious code in ach-detail (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (6c8ce91cbe1aaa587613795b1b82cc84384b499a29af4a18c0a820b77ea1d834) The npm package ach-detail@99.0.1 ships a preinstall lifecycle script (scripts/preinstall.js) that runs automatically on `npm install`. The script collects the installer's hostname, package name and version, Node.js version, platform, timestamp, and a nonce, and POSTs the payload to a hardcoded remote endpoint at https://callback.kuldeep.io/beacon, with an HTTP fallback to the same host. The package is published to the public npm registry at version 99.0.1 — a version-inflation pattern consistent with dependency-confusion targeting of a private internal package of the same name. A log string in the script self-labels the behavior as an authorized bug-bounty PoC, but that label is author-controlled, does not change the observable behavior, and does not represent consent from any installer that resolves the package (accidentally or through dependency-confusion). Installer-side host identifiers leave the machine to a non-first-party endpoint on install.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for ach-detail (npm). Pin to a known-safe version or switch to an alternative.