MAL-2024-2355
Malicious code in faceplate-docs (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (f5198954164869432a0fda9f3f723c1db53531ab2f73db84523e6f62946cf420) faceplate-docs@99.9.10 runs index.js from a postinstall hook that collects the installer's OS username, current working directory, hostname, and local IPv4 address and POSTs them as JSON to a hardcoded anonymous collector at https://webhook.site/f9bff304-3053-4d54-be05-86537267514a. The beacon fires automatically on `npm install` without any user interaction. The package name plus implausibly high version (99.9.10) and the recon-only payload are characteristic of a dependency-confusion probe designed to identify internal build environments that mistakenly resolve a private package name from the public registry.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for faceplate-docs (npm). Pin to a known-safe version or switch to an alternative.