MAL-2026-14356
Malicious code in lumen-pages-community (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (b7c1d6b7b99791f7bbd5999021f109bef569a6c681eda0bb6196b459b12a3808) lumen-pages-community@9.9.9 declares a postinstall hook (`node dc.js`) that runs automatically on `npm install`. dc.js collects the installer's hostname, username, current working directory, platform, Node version, CI environment variable, and npm user-agent, then issues an HTTPS GET to a hardcoded webhook.site collector URL (https://webhook.site/b00492c6-27ba-4ea0-a9cb-dd50b3770250/dc) with those fields as query parameters. The package name plus a 9.9.9 version and no library functionality matches the dependency-confusion shape: a high-version public namesake that catches internal-name resolution and phones home from any host that resolves it. A self-labeled 'research placeholder' framing in the package description does not change the runtime behavior — installer identifiers leave the host at install time to a third-party collector the installer did not opt into.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for lumen-pages-community (npm). Pin to a known-safe version or switch to an alternative.