MAL-2026-14249
Malicious code in localize-extract (npm)
상세
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (265d3f1cc9dae0e1599e17054e0cebe1481224741d3c3dce5d78916feebd5da2) localize-extract@1.0.0 executes a postinstall script that collects host identifiers (os.hostname(), platform, arch, node version, package name, lifecycle event) and POSTs them as JSON to the hardcoded endpoint https://1zrgq9h2.instances.poc.jchunt.top/localize-extract at npm install time. The package name resembles @angular/localize and the tarball references the upstream angular/localize package.json, consistent with a dependency-confusion / typosquat probe. Data leaves the installer's machine to an attacker-chosen host without consent on install.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
No fixed version published yet for localize-extract (npm). Pin to a known-safe version or switch to an alternative.