MAL-2026-16311
Malicious code in test12vv36 (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (9292921d0fe368160694717f99eca753070a4249696c72b2f1bff9594cab40be) test12vv36@99.99.99 declares both preinstall and postinstall lifecycle hooks that execute index.js on npm install. index.js issues an HTTP GET to a hardcoded bare-IP endpoint at http://128.199.122.145/?test12vv36, sending the package name in the query string and disclosing the installer's source IP to the operator of that host. The version number (99.99.99) and package.json shape (dependency on a typosquat name 'requests@^0.3.0' plus a duplicate misspelled 'Dependencies' key) are consistent with a dependency-confusion or proof-of-concept publish rather than a functional library. Installing the package causes unauthenticated, unencrypted outbound network activity to attacker-controlled infrastructure at install time, confirming successful installation on the host.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for test12vv36 (npm). Pin to a known-safe version or switch to an alternative.