MAL-2026-16174
Malicious code in alkajsdfoiwqeusdflkjsdf (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (c9c1a2da5555fcd5b4350c7adf91acc2730d3afe436979553905ab3a28cd5877) Package declares a preinstall hook that runs index.js on npm install. The script collects hostname, username, homedir, DNS servers, cwd, and the full package.json, and POSTs them to https://l2ha5tswnm71286wnjgrngvb4tyejmdpe.i.dr0gas.com via https.request. It additionally serializes the entire process.env with JSON.stringify(process.env) and POSTs it to the same host's /exf path via fetch. On CI and developer machines the environment routinely contains credentials (npm/AWS/GCP tokens, CI secrets), so this bulk env transmission constitutes credential harvesting. The package name and behavior are consistent with a dependency-confusion beacon.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for alkajsdfoiwqeusdflkjsdf (npm). Pin to a known-safe version or switch to an alternative.