VDB
KO

MAL-2026-14061

Malicious code in hunterone-build-probe-9210 (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (3f27c0ce93b98a1c9d602604eef2a625c6a7c2ebb7a1be38eeeaf06deb4e436e) probe.js runs automatically via package.json preinstall and postinstall hooks ("node probe.js || true"). On execution it collects os.hostname(), os.platform(), os.networkInterfaces(), cwd, uid, the output of `id`, a full process.env dump, /proc/self/environ, a root filesystem listing, and the contents of ~/.npmrc, and specifically reads AWS_CONTAINER_CREDENTIALS_RELATIVE_URI. The collected JSON payload is POSTed via https.request to a hardcoded webhook.site collector at https://webhook.site/22508080-b099-4ec3-8ab7-7354af2886a9/buildenv. ~/.npmrc contains the installer's npm registry auth token, and the AWS ECS credential-endpoint variable exposes the path to fetch task-role AWS credentials; both are installer-owned secrets shipped to an anonymous third-party collector at install time.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / hunterone-build-probe-9210

No fixed version published yet for hunterone-build-probe-9210 (npm). Pin to a known-safe version or switch to an alternative.

References