MAL-2026-15565
Malicious code in @testrelic/playwright-analytics (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (c305bbe247587c98b06f039cdcf78066dbcd4fdacf5a5de0411023c2a4fcc97a) scripts/postinstall.cjs is registered as the package's postinstall lifecycle script and runs automatically on `npm install`. After a block of legitimate-looking config-scaffolding code, the file contains roughly 7 KB of whitespace padding followed by an obfuscated payload that reconstructs a large string via a custom Fisher–Yates shuffle, resolves the String `constructor` property (Function) to avoid any literal `Function`/`eval` token, and invokes `Function('', decodedBody)(decodedArg)`. Immediately before the invocation the script assigns `require`, `module`, `__dirname`, and `__filename` onto the global object so the decoded body can load arbitrary Node built-ins. The whitespace gap conceals the payload from casual review of the file, and the indirection through `String[constructor]` avoids the literal tokens static reviewers grep for. The bundled `dist/index.cjs`, `dist/reporter-entry.cjs`, and `dist/cli.cjs` additionally contain `require('child_process')` alongside outbound HTTP POST call sites and `ping` invocations. The package's declared identity (a Playwright analytics reporter under an unfamiliar `@testrelic` scope) is inconsistent with shipping an obfuscated postinstall dynamic-code loader.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for @testrelic/playwright-analytics (npm). Pin to a known-safe version or switch to an alternative.