MAL-2026-14248
Malicious code in nice-utils-helper (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (5c88734e4d701b61fd197a942bc057f59c684d4eb9994ca0efc7136dfcf893c9) The npm package nice-utils-helper@1.0.0 executes probe.js from its postinstall lifecycle. On install, probe.js issues requests to cloud instance-metadata service endpoints (AWS 169.254.169.254, Aliyun 100.100.100.200, Tencent metadata.tencentyun.com, 169.254.0.23) using curl/http.request/GET and records per-target reachability along with the host's hostname and cwd. It then writes NCODE_META.txt and NCODE_POC_MARKER.txt into the current directory as well as../ and../.., leaving beacon/marker artifacts above the package root. The package advertises itself as a 'game metadata' utility and self-labels the probing as an 'Authorized PoC', but the executed behavior is unsolicited cloud-environment reconnaissance and cross-directory file writes on the installer's machine at install time, unrelated to any advertised utility functionality.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for nice-utils-helper (npm). Pin to a known-safe version or switch to an alternative.