MAL-2026-14036
Malicious code in notafollower1226 (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (fdc72e98071e37ff58c3bb327f995c9c586b81a22180a8004b6564026cbc629f) The package.json postinstall script auto-executes on npm install. It queries the ECS container metadata endpoint (ECS_CONTAINER_METADATA_URI_V4/task) to collect the Task ARN, container image list, and log group/stream configuration, then enumerates process.env for keys matching /owner|team|user|created|author|maintainer|contact/i, and pipes the resulting report via `curl -X POST --data-binary @-` to the hardcoded anonymous ngrok tunnel https://mourner-slot-explicit.ngrok-free.dev. The destination is not associated with any declared publisher and ngrok-free.dev subdomains are ephemeral anonymous tunnels typical of supply-chain reconnaissance against CI/build infrastructure. The package ships no other functionality consistent with a legitimate declared purpose; its only install-time effect is the exfiltration beacon.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for notafollower1226 (npm). Pin to a known-safe version or switch to an alternative.
References
- https://www.npmjs.com/package/notafollower1226/v/1.0.3 [PACKAGE]
- https://www.npmjs.com/package/notafollower1226/v/1.0.5 [PACKAGE]
- https://www.npmjs.com/package/notafollower1226/v/1.0.2 [PACKAGE]
- https://www.npmjs.com/package/notafollower1226/v/1.0.1 [PACKAGE]
- https://www.npmjs.com/package/notafollower1226/v/1.0.0 [PACKAGE]
- https://www.npmjs.com/package/notafollower1226/v/1.0.4 [PACKAGE]