MAL-2026-13371
Malicious code in multi-acct (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (395e9271172eea5db15a1090043ee564ad6b8564fb9e267faff883ac3c6af125) multi-acct@99.99.99 is a near-empty wrapper (index.js is a two-line stub returning name/version literals; author is the generic 'Package Registry' and repository.url points at an example.com-style placeholder). Its sole functional dependency, `vector-cursor-stream-engine`, is not resolved from the npm registry but from a hardcoded third-party HTTPS URL, https://artifacts.yosiroute.com/npm/vector-cursor-stream-engine, and the shrinkwrap marks that dependency as hasInstallScript:true. On `npm install`, npm downloads the tarball from artifacts.yosiroute.com and executes its lifecycle scripts, so whoever controls that host gets arbitrary code execution on the installer's machine. The URL is unpinned and carries no integrity hash, so the delivered bytes can change at any time. The wrapper shape (placeholder metadata, trivial main, single off-registry dependency with install scripts) matches a dependency-confusion / lure package whose real payload is delivered through the fetched sub-tarball.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for multi-acct (npm). Pin to a known-safe version or switch to an alternative.
References
- https://www.npmjs.com/package/multi-acct/v/99.99.99 [PACKAGE]
- https://www.npmjs.com/package/multi-acct/v/3.1.0 [PACKAGE]
- https://www.npmjs.com/package/multi-acct/v/4.999.999 [PACKAGE]
- https://www.npmjs.com/package/multi-acct/v/3.0.999 [PACKAGE]
- https://www.npmjs.com/package/multi-acct/v/3.999.999 [PACKAGE]
- https://www.npmjs.com/package/multi-acct/v/2.0.999 [PACKAGE]
- https://www.npmjs.com/package/multi-acct/v/4.0.0 [PACKAGE]
- https://www.npmjs.com/package/multi-acct/v/2.1.999 [PACKAGE]
- https://www.npmjs.com/package/multi-acct/v/1.0.0 [PACKAGE]
- https://www.npmjs.com/package/multi-acct/v/2.999.999 [PACKAGE]