MAL-2026-12496
Malicious code in voicemail (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (568a31285f414d8125b5749bc8e070157ffd403ce46e46da637cc1452f99d19f) package.json declares both preinstall and postinstall lifecycle scripts that invoke curl against a hardcoded webhook.site endpoint (https://webhook.site/d80b4602-8a87-4693-8510-6ff77c62788e/blots) with query parameters carrying the installer's username ($(whoami)), hostname ($(hostname)), current working directory ($PWD), and a timestamp. The beacon fires automatically on `npm install` without user consent, sending host and identity reconnaissance to an attacker-controlled collector. The package provides no legitimate functionality corresponding to this network activity.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for voicemail (npm). Pin to a known-safe version or switch to an alternative.