MAL-2026-16344
Malicious code in sorrawit-dev-helper (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (c64040dcfbbdb6ce434caf3cd5bd2baa518cc00970281a69f5309d57a4621233) package.json declares a postinstall lifecycle script that runs automatically on `npm install`. The script reads /tmp/flag.txt from the installer's machine and sends its URL-encoded contents as a query parameter to a hardcoded ngrok tunnel at https://ca37-49-237-83-218.ngrok-free.app/. The destination is an ephemeral tunnel host unrelated to any legitimate publisher, and the read+exfil fires without user interaction. The behavior matches install-time credential/file exfiltration with a concrete installer-side data source and a concrete attacker-controlled destination.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for sorrawit-dev-helper (npm). Pin to a known-safe version or switch to an alternative.