MAL-2026-14232
Malicious code in chromeos-webdriver-cli (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (1bbf3413f6465a1f8bb628dcdb79f59ac7c197bbfba2024202c9915f95ad8161) The package's postinstall script runs on `npm install` and issues an HTTPS POST to https://kvpq6u62.instances.poc.jchunt.top/chromeos-webdriver-cli carrying installer-identifying fields (os.hostname(), platform, arch, node version, package name, timestamp). The destination is a hardcoded non-first-party host reached without user consent or configuration. The subdomain shape (random-token under instances.poc.jchunt.top) is consistent with a dependency-confusion / typo-squat canary beacon that discloses internal hostnames and environment metadata to a third party at install time.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for chromeos-webdriver-cli (npm). Pin to a known-safe version or switch to an alternative.