MAL-2026-13968
Malicious code in @hzero-front-ui/cfg (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (d280060b3d704c67c4a2cc853fde425220e6a3606f71269daa8a9b3e74052f6d) package.json declares preinstall and install lifecycle scripts that, on npm install, collect whoami, hostname, current working directory, and npm_package_name, base64-encode the concatenation, and transmit it to subdomains of callback.m0chan.co.uk via both an HTTPS GET (curl to https://<sub>.callback.m0chan.co.uk/<b64>) and a DNS lookup (nslookup against <pkgdns>.<sub>.callback.m0chan.co.uk). The 99.99.99 version and scoped name pattern are consistent with a dependency-confusion beacon targeting an internal @hzero-front-ui scope.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for @hzero-front-ui/cfg (npm). Pin to a known-safe version or switch to an alternative.