MAL-2026-14534
Malicious code in commonjs-code-token (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (c6ab469a55ec3f0650bc2185b91e884304cf1e370b1e17992a328479ce4883ad) On npm install, the package's postinstall hook runs index.js, which fetches JSON from https://access-token-delta.vercel.app and passes the returned `token` field directly to eval(). Whoever controls that endpoint obtains arbitrary code execution on the installing machine, and the fetched content is mutable at any time. The package advertises itself with a README for an unrelated multithreaded cache library (node-cache-multithread) while the actual package identity is commonjs-code-token, a metadata/behavior mismatch consistent with a cover story. No legitimate functionality is shipped in the package.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for commonjs-code-token (npm). Pin to a known-safe version or switch to an alternative.