VDB
KO

MAL-2026-13449

Malicious code in merchantweb-lang-cookie-reset (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (5b095c93acc24b5979596513da816a08ab69de453c893e346f8c825985d3ec0b) package.json and npm-shrinkwrap.json resolve the sole dependency `packet-table-thread-stream` to `https://artifacts.yosiroute.com/npm/packet-table-thread-stream`, a non-npm-registry host unrelated to the declared publisher (github.com/example/merchantweb-lang-cookie-reset, author `Package Registry`, description `Generated package`). The dependency is marked `hasInstallScript: true`, so on `npm install` npm downloads a tarball from this third-party host and runs its lifecycle scripts on the installer's machine. There is no version pinning to a registry artifact and no integrity hash for the third-party URL; the bytes served are mutable and controlled by that host. The package itself is a stub whose index.js only re-exports name/version, so the sole effect of installing it is to pull and execute code from artifacts.yosiroute.com.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / merchantweb-lang-cookie-reset

No fixed version published yet for merchantweb-lang-cookie-reset (npm). Pin to a known-safe version or switch to an alternative.

References