VDB
KO

MAL-2026-14251

Malicious code in ngsw-config (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (8b427c73f093ad680033b2779c43c1c96186a71055aaff3cf44befd18c2cecbd) The package's postinstall lifecycle script collects installer host identifiers (hostname, platform, architecture, Node version, package/lifecycle name, timestamp) and POSTs them as JSON to the hardcoded endpoint https://wxc97jnc.instances.poc.jchunt.top/ngsw-config on npm install, with no consent, documentation, or opt-out. The package name shadows Angular's legitimate ngsw-config tooling, matching a dependency-confusion canary pattern in which internal build systems that misresolve the name automatically report identifying metadata to the operator of the poc.jchunt.top host.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / ngsw-config

No fixed version published yet for ngsw-config (npm). Pin to a known-safe version or switch to an alternative.

References