VDB
Sign up

MAL-2026-16218

Malicious code in tol8t (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (c33f4cd3c64d0ca0eb65dc5947fce3700c94ec8bea6083e63da1e6ba31321e27) package.json declares preinstall and postinstall lifecycle hooks that use wget to POST installer host identifiers to a hardcoded Discord webhook at https://discord.com/api/webhooks/1413937656697720862/. The preinstall hook sends the installer's current working directory ($(pwd)) and the postinstall hook sends the machine hostname ($(hostname)). Both fire automatically during `npm install` with no user interaction. The package ships no other functionality; its sole behavior is host reconnaissance beaconing to an attacker-controlled Discord webhook.

## Source: ossf-package-analysis (2f9850f64422a733207e07792098b0e3c72d43311f73a44bd07ae0c2dd4429eb) The OpenSSF Package Analysis project identified 'tol8t' @ 14.0.0 (npm) as malicious.

It is considered malicious because:

- The package communicates with a domain associated with malicious activity.

- The package executes one or more commands associated with malicious behavior.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/tol8t

No fixed version published yet for tol8t (npm). Pin to a known-safe version or switch to an alternative.

References