VDB
EN

MAL-2026-14034

Malicious code in notafollower1 (npm)

상세

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (7c74ec5369dac32115a9f5f257f512fa0a48d2e914b1f18c5178992b0a1604f9) package.json declares a postinstall script that automatically runs on npm install and fetches AWS ECS container task metadata via the ECS_CONTAINER_METADATA_URI_V4 endpoint (task ARN, container names, image names), then POSTs the collected data to a hardcoded ngrok tunnel at https://mourner-slot-explicit.ngrok-free.dev using curl. The postinstall also inspects the container image name for substrings matching known security research operators (twbray, packagehound, wiz, oss-dynamic) and labels the payload accordingly, indicating deliberate sandbox and analyst fingerprinting. The destination is an anonymous ngrok tunnel unrelated to any legitimate publisher infrastructure, and the collected data reveals installer-side CI/build/container environment details to a third party.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / notafollower1

No fixed version published yet for notafollower1 (npm). Pin to a known-safe version or switch to an alternative.

참고