MAL-2026-16113
Malicious code in etoro-api (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (ab6228f994962694d4434f53d20d6a5a1b877b39a3498236327da9d0385284d9) The preinstall lifecycle script in etoro-api@999.0.0 (preinstall.js) auto-executes on npm install and performs an HTTP GET to a hardcoded bare-IP endpoint at http://209.126.81.147/etoro-depconf-poce346552f776f/npm/<host>/<user>/<cwd>, embedding the installer's hostname (os.hostname()), OS username (os.userInfo().username), and current working directory (process.cwd()) as URL path components. The destination is a plain-HTTP bare-IP host unrelated to any legitimate eToro publishing infrastructure. The package name combined with the implausibly high version number (999.0.0) is the canonical dependency-confusion shape used to force resolution over an internal private package of the same name.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for etoro-api (npm). Pin to a known-safe version or switch to an alternative.