VDB
KO

MAL-2026-14134

Malicious code in @mohamed_nowisar/depconf-canary-test (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (078a8dc3351eb44ee9ff0d5992b9082b726d7fbce0152ae2d44595a9e279ef82) On `npm install`, the package's preinstall hook runs `node beacon.js`, which collects host identity (os.hostname(), os.userInfo().username, process.cwd(), platform, arch, Node version) and CI-detection environment variables (GITLAB_CI, GITHUB_ACTIONS, YANDEX_CI, and others) and POSTs them as JSON to the hardcoded endpoint https://webhook.site/3687e44a-4e97-43c4-84c9-e6c93d4b2fbc. The package name and self-description frame this as a dependency-confusion canary, but the beacon fires automatically on install without opt-in and sends installer-side data to an author-controlled webhook.site collector.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / @mohamed_nowisar/depconf-canary-test

No fixed version published yet for @mohamed_nowisar/depconf-canary-test (npm). Pin to a known-safe version or switch to an alternative.

References