MAL-2026-15627
Malicious code in hyperliquid-composer (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (1fb2b7d17a47aa4fcd585374f33063197f52d6ba8619e4105ae5a1d30331bb62) bin/cli.js (also declared as the package main) collects the installer's username via `whoami` / `os.userInfo()`, plus `os.hostname()` and platform, and POSTs them to the hardcoded Cloudflare Workers endpoint https://oobme.kunalsharma0553.workers.dev/r/7bq6fz3l15r9. The exfiltration fires on `require()` of the module or on CLI invocation, with no user consent or configuration. The package name resembles legitimate Hyperliquid tooling.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for hyperliquid-composer (npm). Pin to a known-safe version or switch to an alternative.