VDB
KO

MAL-2026-14534

Malicious code in commonjs-code-token (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (c6ab469a55ec3f0650bc2185b91e884304cf1e370b1e17992a328479ce4883ad) On npm install, the package's postinstall hook runs index.js, which fetches JSON from https://access-token-delta.vercel.app and passes the returned `token` field directly to eval(). Whoever controls that endpoint obtains arbitrary code execution on the installing machine, and the fetched content is mutable at any time. The package advertises itself with a README for an unrelated multithreaded cache library (node-cache-multithread) while the actual package identity is commonjs-code-token, a metadata/behavior mismatch consistent with a cover story. No legitimate functionality is shipped in the package.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / commonjs-code-token

No fixed version published yet for commonjs-code-token (npm). Pin to a known-safe version or switch to an alternative.

References