VDB
Sign up

MAL-2026-16115

Malicious code in etoro-billing (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (3c1ceae274b450706288722b9f6c049114593ef2671de93ac58c4fd4a7318c9a) On `npm install`, the package's `preinstall` lifecycle hook executes `preinstall.js`, which reads `os.hostname()`, `os.userInfo().username`, and `process.cwd()` and issues an HTTP GET to `http://209.126.81.147/etoro-depconf-poce346552f776f/npm/<hostname>/<username>/<cwd>`. The destination is a hardcoded bare-IP over plain HTTP, unrelated to any documented eToro infrastructure. `index.js` is an empty stub (`module.exports = {}`), so the only effect of installing this package is the identifier beacon. The package name claims eToro affiliation and is published as version 999.0.0, a high-version pattern used to win resolution against an internal package of the same name (dependency confusion).

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/etoro-billing

No fixed version published yet for etoro-billing (npm). Pin to a known-safe version or switch to an alternative.

References