MAL-2026-16063
Malicious code in alloy-graphql (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (80ee3815d12ec95aedb4bbe0d3de5c516e99163ca1eba52c2a3de7038b9a2ac0) package.json declares a preinstall hook that runs index.js on npm install. The script collects hostname, username, home directory, DNS servers, current working directory, and package.json contents, and reads /etc/passwd and /etc/hosts from the installer's host. The collected data is HTTPS-POSTed to a hardcoded Burp Collaborator subdomain at ipbtwv9063nc5hvhodh0s4u9x03rrhf6.oastify.com. The package has no advertised functionality beyond this exfiltration payload.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for alloy-graphql (npm). Pin to a known-safe version or switch to an alternative.