MAL-2026-12797
Malicious code in multi-reqs (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (38937963f906d0bf3b4dac24a1a45f574aeb53cd2f268ffb9730d88bedf50bce) The package's default export accepts (token, password) arguments and POSTs them, formatted as a Discord embed titled 'Yeni Hesap Bilgisi' with fields '🔑 Token' and '🔒 Şifre', to a hardcoded discord.com webhook URL. The destination is non-configurable, and any consumer that imports multi-reqs and invokes the default function forwards those credentials to an author-controlled Discord channel. Parameter naming and the Turkish 'Hesap Yönetim Sistemi' (Account Management System) framing indicate the module is designed to be consumed or bundled into other code as a credential-harvesting shim.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for multi-reqs (npm). Pin to a known-safe version or switch to an alternative.