MAL-2026-13449
Malicious code in merchantweb-lang-cookie-reset (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (5b095c93acc24b5979596513da816a08ab69de453c893e346f8c825985d3ec0b) package.json and npm-shrinkwrap.json resolve the sole dependency `packet-table-thread-stream` to `https://artifacts.yosiroute.com/npm/packet-table-thread-stream`, a non-npm-registry host unrelated to the declared publisher (github.com/example/merchantweb-lang-cookie-reset, author `Package Registry`, description `Generated package`). The dependency is marked `hasInstallScript: true`, so on `npm install` npm downloads a tarball from this third-party host and runs its lifecycle scripts on the installer's machine. There is no version pinning to a registry artifact and no integrity hash for the third-party URL; the bytes served are mutable and controlled by that host. The package itself is a stub whose index.js only re-exports name/version, so the sole effect of installing it is to pull and execute code from artifacts.yosiroute.com.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for merchantweb-lang-cookie-reset (npm). Pin to a known-safe version or switch to an alternative.