MAL-2026-13974
Malicious code in @khaznatech/core (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (820c7f4f32895ef501e6926f624897cf41b5f868bc21c60852cbfc101b4cd5ba) The package ships install-report.js as a preinstall lifecycle script that unconditionally runs on npm install. The script reads os.hostname() and the current working directory basename and transmits them via https.get to a hardcoded third-party collector at https://webhook.site/93b065ab-227f-4253-b940-361d00e9b870/, appending the host identifiers as the URL path. The destination is an anonymous request-inspection endpoint unrelated to any declared package purpose, and the beacon fires silently on every installation without opt-in.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for @khaznatech/core (npm). Pin to a known-safe version or switch to an alternative.