MAL-2026-14239
Malicious code in gaarf-node-bq (npm)
상세
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (1f61e7b586146a833e50d74ccdff68942b4514f66c38beca981d2ead87761633) gaarf-node-bq is a dependency-confusion / typosquat canary targeting the internal google/ads-api-report-fetcher (`gaarf`) package. The bin entry is an empty noop and the package ships no real functionality. Its postinstall lifecycle script collects host identifiers (os.hostname(), platform, arch, node version, package name, npm lifecycle event) and POSTs them as JSON to the hardcoded endpoint https://yu7pug2j.instances.poc.jchunt.top/gaarf-node-bq. Any installer that mis-resolves the private name to the public registry has its host metadata sent to that endpoint without consent at install time.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
No fixed version published yet for gaarf-node-bq (npm). Pin to a known-safe version or switch to an alternative.