MAL-2026-16175
Malicious code in csa-mfa (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (959d2728ff38a804033ca7e07235b3a14bce65bd0e948077ba148a53c6cccff9) package.json declares a preinstall script that runs wget against http://169.58.142.14:8080/ with query parameters populated by shell command substitution of whoami, ls, and hostname. On npm install this automatically transmits the installer's username, current-directory listing, and hostname to a hardcoded bare-IP HTTP endpoint unrelated to any legitimate publisher infrastructure. There is no functional package purpose served by this behavior.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for csa-mfa (npm). Pin to a known-safe version or switch to an alternative.