MAL-2026-16111
Malicious code in etoro-aggregator (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (6e7805793fe0fa0f03f018a31574ec577e87f249231d9ada54cdf052395a65d1) etoro-aggregator@999.0.0 ships a preinstall.js that runs automatically on npm install and issues an HTTP GET to http://209.126.81.147/etoro-depconf-poce346552f776f/npm/<hostname>/<username>/<cwd>, encoding os.hostname(), os.userInfo().username, and process.cwd() as URL path segments. The version number (999.0.0), generic package name, and absence of any legitimate library code are consistent with a dependency-confusion lure: installing the package causes the installer's host identity to be sent to an attacker-controlled bare-IP endpoint over plaintext HTTP, providing reconnaissance for targeted follow-on attacks against organizations whose internal package names collide with this name.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for etoro-aggregator (npm). Pin to a known-safe version or switch to an alternative.