VDB
KO

MAL-2026-14249

Malicious code in localize-extract (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (265d3f1cc9dae0e1599e17054e0cebe1481224741d3c3dce5d78916feebd5da2) localize-extract@1.0.0 executes a postinstall script that collects host identifiers (os.hostname(), platform, arch, node version, package name, lifecycle event) and POSTs them as JSON to the hardcoded endpoint https://1zrgq9h2.instances.poc.jchunt.top/localize-extract at npm install time. The package name resembles @angular/localize and the tarball references the upstream angular/localize package.json, consistent with a dependency-confusion / typosquat probe. Data leaves the installer's machine to an attacker-chosen host without consent on install.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / localize-extract

No fixed version published yet for localize-extract (npm). Pin to a known-safe version or switch to an alternative.

References