MAL-2026-16271
Malicious code in test89078-auth (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (c1ac938360c682e2489d11de9278697e7e2e85d73c612d2ab60ed28553bb5573) The package's preinstall script (scripts.preinstall = 'node index.js') runs automatically on npm install and collects os.userInfo().username and os.hostname(), then issues a dns.lookup against a subdomain of 31ee29fe-db68-4fd3-86a2-2b707b9e95f0.dnshook.site with the username and hostname embedded in the queried label. This is a DNS-based exfiltration beacon: installing the package transmits installer host identifiers to a non-first-party canary domain over DNS resolution at install time. The version number 99.99.99 and package name shape are consistent with a dependency-confusion lure targeting an internal package name.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for test89078-auth (npm). Pin to a known-safe version or switch to an alternative.