MAL-2026-16118
Malicious code in etoro-charts (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (484ce8002025d68c4a60feca03aec63425a66b85e2465415a4fc5a29e3a61f43) The package's preinstall.js runs automatically on npm install and issues an HTTP GET to a hardcoded bare IP (http://209.126.81.147/etoro-depconf-poce346552f776f/npm/<hostname>/<username>/<cwd>), embedding the installer's OS hostname (os.hostname()), OS username (os.userInfo().username), and current working directory (process.cwd()) as URL path segments. The package uses a generic 'eToro' brand name with a version pinned at 999.0.0, a pattern consistent with dependency-confusion attacks that aim to win resolution against an internal package of the same name. Installing the package causes installer-side identifiers to be sent in cleartext to an attacker-controlled endpoint.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for etoro-charts (npm). Pin to a known-safe version or switch to an alternative.