MAL-2026-16218
Malicious code in tol8t (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (c33f4cd3c64d0ca0eb65dc5947fce3700c94ec8bea6083e63da1e6ba31321e27) package.json declares preinstall and postinstall lifecycle hooks that use wget to POST installer host identifiers to a hardcoded Discord webhook at https://discord.com/api/webhooks/1413937656697720862/. The preinstall hook sends the installer's current working directory ($(pwd)) and the postinstall hook sends the machine hostname ($(hostname)). Both fire automatically during `npm install` with no user interaction. The package ships no other functionality; its sole behavior is host reconnaissance beaconing to an attacker-controlled Discord webhook.
## Source: ossf-package-analysis (2f9850f64422a733207e07792098b0e3c72d43311f73a44bd07ae0c2dd4429eb) The OpenSSF Package Analysis project identified 'tol8t' @ 14.0.0 (npm) as malicious.
It is considered malicious because:
- The package communicates with a domain associated with malicious activity.
- The package executes one or more commands associated with malicious behavior.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for tol8t (npm). Pin to a known-safe version or switch to an alternative.