MAL-2026-16313
Malicious code in test1gg234 (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (dd57f799e0797ede7d18d6a36dd05c31c34d21b4e45d554730a8d08dd310cf73) The package declares both preinstall and postinstall lifecycle hooks that execute index.js, which issues a plaintext HTTP GET to the hardcoded bare IP 128.199.122.145 with the package name in the query string. The beacon fires unconditionally on npm install, confirming to the operator of that host that the package was resolved and installed on the target machine. The package has no other functionality: an empty description, an inflated version (99.99.99), and a manifest that declares a lookalike dependency `requests` alongside a duplicate capitalized `Dependencies` key referencing `request` — the shape of a dependency-confusion probe rather than a functional library.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for test1gg234 (npm). Pin to a known-safe version or switch to an alternative.