MAL-2026-16112
Malicious code in etoro-analytics (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (a87dfbd5f51b30470e8d1df702e746f7c8141fdaafab2237fd1f2ef4897d9ae5) The package's preinstall lifecycle script runs automatically on `npm install` and sends the installer's hostname, OS username, and current working directory to a hardcoded remote host at http://209.126.81.147 over plain HTTP, embedding the values as URL path segments under `/etoro-depconf-poce346552f776f/npm/`. The destination is a bare IP address, not configurable, and unrelated to any legitimate publisher infrastructure. The `999.0.0` version and eToro-themed name are consistent with a dependency-confusion lure targeting an internal package name.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for etoro-analytics (npm). Pin to a known-safe version or switch to an alternative.