MAL-2026-16306
Malicious code in @nimbusedge2/xa (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (537505221bc3cd73b0d5a60062d6ad127211b2d1be1f1cdfdac13053e2224a11) package.json declares a preinstall lifecycle script that runs an interactive bash reverse shell to the hardcoded host 147.93.157.202.nip.io on TCP port 8080 and pipes the shell's output through curl to http://canarytokens.com/terms/7dc94zmd3so67n5vbz5bxmt7v/contact.php. Because preinstall fires automatically on `npm install`, any machine that installs this package attempts to grant a remote party interactive command execution on the installer's host and unconditionally beacons install-time output over plain HTTP to a third-party tracking endpoint. The nip.io wrapper resolves the bare IP 147.93.157.202 without DNS registration, and the destination and token are hardcoded in the manifest with no caller configuration path.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for @nimbusedge2/xa (npm). Pin to a known-safe version or switch to an alternative.