VDB
Sign up

MAL-2026-16204

Malicious code in @prime0/alanced-match (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (53d49bf28eb233bca0591b32c11b411d1c10b8e8f978d1b76c6df2e6a00772f3) The package @prime0/alanced-match is a 1-character-drop typosquat of balanced-match. Its postinstall.js runs automatically on npm install and POSTs a host fingerprint (hostname, username, platform, arch, cwd, node version, pid, non-internal IP addresses, uptime, package name) to the hardcoded bare-IP endpoint http://69.48.229.140:8080/b. Its main entry index.js opens a require-time HTTP polling channel to the same host, retrieves JSON commands from /c every 30 seconds (with 10-minute re-beacons), executes them via child_process.exec, and posts stdout/stderr back to /r — providing full remote code execution on the installer's machine. A source comment self-identifies the code as a 'Minimal stealth agent' and 'typosquat'.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@prime0/alanced-match

No fixed version published yet for @prime0/alanced-match (npm). Pin to a known-safe version or switch to an alternative.

References