VDB
KO

MAL-2026-14248

Malicious code in nice-utils-helper (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (5c88734e4d701b61fd197a942bc057f59c684d4eb9994ca0efc7136dfcf893c9) The npm package nice-utils-helper@1.0.0 executes probe.js from its postinstall lifecycle. On install, probe.js issues requests to cloud instance-metadata service endpoints (AWS 169.254.169.254, Aliyun 100.100.100.200, Tencent metadata.tencentyun.com, 169.254.0.23) using curl/http.request/GET and records per-target reachability along with the host's hostname and cwd. It then writes NCODE_META.txt and NCODE_POC_MARKER.txt into the current directory as well as../ and../.., leaving beacon/marker artifacts above the package root. The package advertises itself as a 'game metadata' utility and self-labels the probing as an 'Authorized PoC', but the executed behavior is unsolicited cloud-environment reconnaissance and cross-directory file writes on the installer's machine at install time, unrelated to any advertised utility functionality.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / nice-utils-helper

No fixed version published yet for nice-utils-helper (npm). Pin to a known-safe version or switch to an alternative.

References