MAL-2026-14196
Malicious code in tfjs-custom-module (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (c50d87a4593cb5a0444f2333f368180b64dfb5d3b8f37e0baf4f6d686ea2ef74) tfjs-custom-module is a typosquat of the tensorflow/tfjs package. Its package.json declares a postinstall lifecycle script that runs automatically on npm install. The script collects installer host identifiers — os.hostname(), process.platform, process.arch, process.version, package name, and the npm lifecycle event — and POSTs them as JSON via https.request to the hardcoded external host 8xq4kw5d.instances.poc.jchunt.top at path /tfjs-custom-module. The endpoint is not the installer's infrastructure and the beacon is not opt-in. This is host-reconnaissance exfiltration to an author-controlled destination running under a look-alike canary domain, regardless of any self-labeling as security research.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for tfjs-custom-module (npm). Pin to a known-safe version or switch to an alternative.