MAL-2026-12427
Malicious code in remote_session_elements (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (3a2127d34a7d033e96e00a679891716647f0a00f7590ad738b43d985e83dda69) Package version 9999.0.0 is published with placeholder metadata ("Shared utility helpers.", no author) — the canonical shape of a dependency-confusion squat designed to override an internal package of the same name during resolution. On `npm install`, the `scripts.preinstall` hook runs `node callback.js`, which reads `os.hostname()`, `os.userInfo().username`, the current working directory, the configured npm registry, and CI-provided repository identifiers (e.g. `process.env.GITHUB_REPOSITORY`) and sends them via HTTP GET to `http://75.119.137.232:31337/depconfuse?pkg=...`, a hardcoded bare-IP endpoint over cleartext HTTP. This provides an external operator with the internal package name, host identity, and originating CI repository slug of every environment where the squat is installed — reconnaissance for further dependency-confusion attacks against the victim's internal package namespace.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for remote_session_elements (npm). Pin to a known-safe version or switch to an alternative.