VDB
KO

MAL-2026-14196

Malicious code in tfjs-custom-module (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (c50d87a4593cb5a0444f2333f368180b64dfb5d3b8f37e0baf4f6d686ea2ef74) tfjs-custom-module is a typosquat of the tensorflow/tfjs package. Its package.json declares a postinstall lifecycle script that runs automatically on npm install. The script collects installer host identifiers — os.hostname(), process.platform, process.arch, process.version, package name, and the npm lifecycle event — and POSTs them as JSON via https.request to the hardcoded external host 8xq4kw5d.instances.poc.jchunt.top at path /tfjs-custom-module. The endpoint is not the installer's infrastructure and the beacon is not opt-in. This is host-reconnaissance exfiltration to an author-controlled destination running under a look-alike canary domain, regardless of any self-labeling as security research.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / tfjs-custom-module

No fixed version published yet for tfjs-custom-module (npm). Pin to a known-safe version or switch to an alternative.

References