MAL-2026-12492
Malicious code in uploader-frontend-legacy (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (0e90aa99bc8b8e4bb886e911c1fe5ffbddd1d7e730088105118db47170b66681) The package's `scripts.install` runs `node index.js`, which loads `lib/core.js` and issues a `dns.resolve4` query against a subdomain of `oob.sl4x0.xyz` constructed from `os.userInfo().username`, `os.hostname()`, and `process.cwd()`, along with a package tag and timestamp. Module names (`os`, `dns`, `process`), API names (`userInfo`, `hostname`, `cwd`, `resolve4`), and the destination domain `oob.sl4x0.xyz` are assembled from `String.fromCharCode` byte arrays in `lib/b02e30.js`, `lib/6ad264.js`, and `lib/core.js` to hide the behavior from casual review. The net effect on `npm install` is an outbound DNS beacon carrying installer-identifying data to an author-controlled out-of-band listener.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for uploader-frontend-legacy (npm). Pin to a known-safe version or switch to an alternative.