VDB
Sign up

MAL-2026-16342

Malicious code in pflag29424 (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (d9b974c9d8555f026dfc5556c4f628d366fbaedca83eab549559fe95fc984602) index.js (the package's declared main) unconditionally executes on module load: it calls fetch('/profile'), scans the response for a DGA{...} token, and sends either the matched token or the first 300 characters of the response as a query parameter to a hardcoded anonymous collector at https://webhook.site/42c6d937-77c7-42a5-8678-ef06b4501e38. The package has no README, no documented purpose, and a generic throwaway name; the sole effect of loading it is to relay content from the loading context to an attacker-controlled webhook.site endpoint.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/pflag29424

No fixed version published yet for pflag29424 (npm). Pin to a known-safe version or switch to an alternative.

References