VDB
Sign up

MAL-2026-16146

Malicious code in @aiwfm/communitywfm.scripts.api (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (405cd17e3c682b1341db44361500ea68d80e1758f15387d9971d0af95f0c8a48) The package's preinstall script (build.js) assembles a remote hostname from split string fragments that resolve to dawn-salad-18c7.mikhail-nab.workers.dev, base64-encodes the full process.env, and POSTs it to that endpoint on npm install. The exfiltration is gated by sandbox-evasion filters that suppress the request when common analysis-environment signals are present (Chinese mirror registries such as taobao/npmmirror/cnpmjs/tencent, mitmproxy CA via NODE_EXTRA_CA_CERTS, /analysis paths, /root HOME combined with /app PWD, or fewer than ten environment variables). On developer and CI machines process.env routinely contains npm auth tokens, cloud credentials, and other secrets, so this constitutes bulk credential and environment exfiltration to an attacker-controlled Cloudflare Workers endpoint.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@aiwfm/communitywfm.scripts.api

No fixed version published yet for @aiwfm/communitywfm.scripts.api (npm). Pin to a known-safe version or switch to an alternative.

References