VDB
Sign up

MAL-2026-16311

Malicious code in test12vv36 (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (9292921d0fe368160694717f99eca753070a4249696c72b2f1bff9594cab40be) test12vv36@99.99.99 declares both preinstall and postinstall lifecycle hooks that execute index.js on npm install. index.js issues an HTTP GET to a hardcoded bare-IP endpoint at http://128.199.122.145/?test12vv36, sending the package name in the query string and disclosing the installer's source IP to the operator of that host. The version number (99.99.99) and package.json shape (dependency on a typosquat name 'requests@^0.3.0' plus a duplicate misspelled 'Dependencies' key) are consistent with a dependency-confusion or proof-of-concept publish rather than a functional library. Installing the package causes unauthenticated, unencrypted outbound network activity to attacker-controlled infrastructure at install time, confirming successful installation on the host.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/test12vv36

No fixed version published yet for test12vv36 (npm). Pin to a known-safe version or switch to an alternative.

References