MAL-2026-14067
Malicious code in upload-to-gcp (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (4094f90a9780964738c1b9aea702c5554c802fba03f1a7e28c0703531dd04590) upload-to-gcp@3.2.1 runs a postinstall lifecycle script on npm install that collects host identifiers (os.hostname(), process.platform, process.arch, Node version, package name, npm lifecycle event) and POSTs them to a hardcoded remote endpoint at https://z5owtt3g.instances.poc.jchunt.top/upload-to-gcp. The destination is a random-looking subdomain not associated with Google Cloud Platform or any documented first-party service, and the transmission occurs automatically at install time with no opt-in and no disclosure. The package name suggests a GCP upload utility, which is inconsistent with the observed beaconing behavior to an unrelated host.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for upload-to-gcp (npm). Pin to a known-safe version or switch to an alternative.