VDB
Sign up

MAL-2026-16174

Malicious code in alkajsdfoiwqeusdflkjsdf (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (c9c1a2da5555fcd5b4350c7adf91acc2730d3afe436979553905ab3a28cd5877) Package declares a preinstall hook that runs index.js on npm install. The script collects hostname, username, homedir, DNS servers, cwd, and the full package.json, and POSTs them to https://l2ha5tswnm71286wnjgrngvb4tyejmdpe.i.dr0gas.com via https.request. It additionally serializes the entire process.env with JSON.stringify(process.env) and POSTs it to the same host's /exf path via fetch. On CI and developer machines the environment routinely contains credentials (npm/AWS/GCP tokens, CI secrets), so this bulk env transmission constitutes credential harvesting. The package name and behavior are consistent with a dependency-confusion beacon.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/alkajsdfoiwqeusdflkjsdf

No fixed version published yet for alkajsdfoiwqeusdflkjsdf (npm). Pin to a known-safe version or switch to an alternative.

References