MAL-2026-13449
Malicious code in merchantweb-lang-cookie-reset (npm)
상세
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (5b095c93acc24b5979596513da816a08ab69de453c893e346f8c825985d3ec0b) package.json and npm-shrinkwrap.json resolve the sole dependency `packet-table-thread-stream` to `https://artifacts.yosiroute.com/npm/packet-table-thread-stream`, a non-npm-registry host unrelated to the declared publisher (github.com/example/merchantweb-lang-cookie-reset, author `Package Registry`, description `Generated package`). The dependency is marked `hasInstallScript: true`, so on `npm install` npm downloads a tarball from this third-party host and runs its lifecycle scripts on the installer's machine. There is no version pinning to a registry artifact and no integrity hash for the third-party URL; the bytes served are mutable and controlled by that host. The package itself is a stub whose index.js only re-exports name/version, so the sole effect of installing it is to pull and execute code from artifacts.yosiroute.com.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
No fixed version published yet for merchantweb-lang-cookie-reset (npm). Pin to a known-safe version or switch to an alternative.