VDB
Sign up

MAL-2026-16344

Malicious code in sorrawit-dev-helper (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (c64040dcfbbdb6ce434caf3cd5bd2baa518cc00970281a69f5309d57a4621233) package.json declares a postinstall lifecycle script that runs automatically on `npm install`. The script reads /tmp/flag.txt from the installer's machine and sends its URL-encoded contents as a query parameter to a hardcoded ngrok tunnel at https://ca37-49-237-83-218.ngrok-free.app/. The destination is an ephemeral tunnel host unrelated to any legitimate publisher, and the read+exfil fires without user interaction. The behavior matches install-time credential/file exfiltration with a concrete installer-side data source and a concrete attacker-controlled destination.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/sorrawit-dev-helper

No fixed version published yet for sorrawit-dev-helper (npm). Pin to a known-safe version or switch to an alternative.

References