VDB
Sign up

MAL-2026-16112

Malicious code in etoro-analytics (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (a87dfbd5f51b30470e8d1df702e746f7c8141fdaafab2237fd1f2ef4897d9ae5) The package's preinstall lifecycle script runs automatically on `npm install` and sends the installer's hostname, OS username, and current working directory to a hardcoded remote host at http://209.126.81.147 over plain HTTP, embedding the values as URL path segments under `/etoro-depconf-poce346552f776f/npm/`. The destination is a bare IP address, not configurable, and unrelated to any legitimate publisher infrastructure. The `999.0.0` version and eToro-themed name are consistent with a dependency-confusion lure targeting an internal package name.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/etoro-analytics

No fixed version published yet for etoro-analytics (npm). Pin to a known-safe version or switch to an alternative.

References