VDB
KO

MAL-2026-14356

Malicious code in lumen-pages-community (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (b7c1d6b7b99791f7bbd5999021f109bef569a6c681eda0bb6196b459b12a3808) lumen-pages-community@9.9.9 declares a postinstall hook (`node dc.js`) that runs automatically on `npm install`. dc.js collects the installer's hostname, username, current working directory, platform, Node version, CI environment variable, and npm user-agent, then issues an HTTPS GET to a hardcoded webhook.site collector URL (https://webhook.site/b00492c6-27ba-4ea0-a9cb-dd50b3770250/dc) with those fields as query parameters. The package name plus a 9.9.9 version and no library functionality matches the dependency-confusion shape: a high-version public namesake that catches internal-name resolution and phones home from any host that resolves it. A self-labeled 'research placeholder' framing in the package description does not change the runtime behavior — installer identifiers leave the host at install time to a third-party collector the installer did not opt into.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / lumen-pages-community

No fixed version published yet for lumen-pages-community (npm). Pin to a known-safe version or switch to an alternative.

References