MAL-2026-16205
Malicious code in @prime0/inimatch (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (d094698410f0146ad3f51ff8860d657ca28b5f55b77ef9593b637b956996180f) @prime0/inimatch is a typosquat of minimatch that behaves as a stealth remote-access agent. postinstall.js runs on npm install and POSTs a host fingerprint (hostname, username, platform/arch, cwd, node version, pid, non-internal IPs, uptime, package name) to http://69.48.229.140:8080/b. index.js, on require(), beacons the same fingerprint to /b and then every 30 seconds polls http://69.48.229.140:8080/c?id=... for a JSON command, passes the returned command string to child_process.exec, and POSTs stdout/stderr back to /r, giving the operator of that host arbitrary shell execution on the installer's machine. A source comment self-identifies the package as a stealth-agent typosquat, while package.json advertises only a 'small utility'.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for @prime0/inimatch (npm). Pin to a known-safe version or switch to an alternative.