VDB
KO

MAL-2026-12334

Malicious code in ach-detail (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (6c8ce91cbe1aaa587613795b1b82cc84384b499a29af4a18c0a820b77ea1d834) The npm package ach-detail@99.0.1 ships a preinstall lifecycle script (scripts/preinstall.js) that runs automatically on `npm install`. The script collects the installer's hostname, package name and version, Node.js version, platform, timestamp, and a nonce, and POSTs the payload to a hardcoded remote endpoint at https://callback.kuldeep.io/beacon, with an HTTP fallback to the same host. The package is published to the public npm registry at version 99.0.1 — a version-inflation pattern consistent with dependency-confusion targeting of a private internal package of the same name. A log string in the script self-labels the behavior as an authorized bug-bounty PoC, but that label is author-controlled, does not change the observable behavior, and does not represent consent from any installer that resolves the package (accidentally or through dependency-confusion). Installer-side host identifiers leave the machine to a non-first-party endpoint on install.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / ach-detail

No fixed version published yet for ach-detail (npm). Pin to a known-safe version or switch to an alternative.

References