MAL-2026-14424
Malicious code in @medisend/webview-bridge (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (ddf4b396c306b8f8d090b929c265b8ae848c75e53b9750d6f68800a4deefe9a2) package.json declares a postinstall lifecycle script that runs curl to https://webhook.site/74ed1be3-96d6-48c3-932b-6b1dbabaff97 with query parameters populated from $(whoami), $(hostname), $(pwd), $(ls -la), and $(node -v). On every npm install the installer's username, hostname, working directory, a directory listing of the install location, and Node.js version are sent to a third-party webhook.site collector controlled by whoever provisioned that endpoint. The package publishes under the @medisend scope and its description states a dependency-confusion test referencing a third-party VDP; an installer whose internal tooling resolves the public registry version instead of an internal @medisend package will trigger this exfiltration automatically.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for @medisend/webview-bridge (npm). Pin to a known-safe version or switch to an alternative.