MAL-2026-14394
Malicious code in sm-apikey-model (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (d8e5a8bc4d985b445afbc71bd563bcee445381d2539a7110a0ca53d54b800367) package.json declares preinstall and postinstall lifecycle scripts that invoke curl over plain HTTP to a hardcoded bare-IP endpoint (http://16.192.173.5/sm-apikey-model/pre and.../post). The path segment embeds the package name, so the operator of that endpoint receives a callback confirming each host that installed this specific package, along with the installer's source IP. The version number (99.0.0) and the dependency-confusion beacon shape are consistent with a namespace-squat reconnaissance package rather than a functional library.
## Source: ossf-package-analysis (58440b7c774647b07278e54b62e08591a1f106b1e0dfb2f597fd3663512ab427) The OpenSSF Package Analysis project identified 'sm-apikey-model' @ 99.0.1 (npm) as malicious.
It is considered malicious because:
- The package executes one or more commands associated with malicious behavior.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for sm-apikey-model (npm). Pin to a known-safe version or switch to an alternative.