MAL-2026-15825
Malicious code in real-router-utils (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (f91fd520ae94997277ef7d591d30dc728b895611fd45b890e2ec1a68233e29a8) package.json declares a preinstall script that runs an inline node command reading the installer's OS hostname, username, and current working directory and sending them as query parameters to a hardcoded webhook.site collector URL (https://webhook.site/e32d3b8a-a5df-40cc-ae60-7a8343b581e4). The request fires automatically on npm install, before any user interaction, and the destination is an anonymous ephemeral webhook endpoint unrelated to any documented package purpose.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for real-router-utils (npm). Pin to a known-safe version or switch to an alternative.