MAL-2026-14061
Malicious code in hunterone-build-probe-9210 (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (3f27c0ce93b98a1c9d602604eef2a625c6a7c2ebb7a1be38eeeaf06deb4e436e) probe.js runs automatically via package.json preinstall and postinstall hooks ("node probe.js || true"). On execution it collects os.hostname(), os.platform(), os.networkInterfaces(), cwd, uid, the output of `id`, a full process.env dump, /proc/self/environ, a root filesystem listing, and the contents of ~/.npmrc, and specifically reads AWS_CONTAINER_CREDENTIALS_RELATIVE_URI. The collected JSON payload is POSTed via https.request to a hardcoded webhook.site collector at https://webhook.site/22508080-b099-4ec3-8ab7-7354af2886a9/buildenv. ~/.npmrc contains the installer's npm registry auth token, and the AWS ECS credential-endpoint variable exposes the path to fetch task-role AWS credentials; both are installer-owned secrets shipped to an anonymous third-party collector at install time.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for hunterone-build-probe-9210 (npm). Pin to a known-safe version or switch to an alternative.
References
- https://www.npmjs.com/package/hunterone-build-probe-9210/v/1.0.5 [PACKAGE]
- https://www.npmjs.com/package/hunterone-build-probe-9210/v/1.0.3 [PACKAGE]
- https://www.npmjs.com/package/hunterone-build-probe-9210/v/1.0.6 [PACKAGE]
- https://www.npmjs.com/package/hunterone-build-probe-9210/v/1.0.1 [PACKAGE]
- https://www.npmjs.com/package/hunterone-build-probe-9210/v/1.0.0 [PACKAGE]
- https://www.npmjs.com/package/hunterone-build-probe-9210/v/1.0.2 [PACKAGE]
- https://www.npmjs.com/package/hunterone-build-probe-9210/v/1.0.7 [PACKAGE]
- https://www.npmjs.com/package/hunterone-build-probe-9210/v/1.0.4 [PACKAGE]