MAL-2026-16354
Malicious code in @woodpecker-web-shared/components (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (5f5f21bcc5464689c5b7c70819eeca4ea481f76b5f7dac0358cfe2d967da235f) On `npm install`, the package's postinstall hook runs `node index.js`, which collects installer host identifiers (os.hostname(), os.userInfo().username, os.platform(), architecture, cwd, node version, npm_lifecycle_event) and POSTs them as JSON to a hardcoded third-party collector at https://webhook.site/d9bc4bcc-ce74-4193-ae4e-96d234bb2220. The payload includes a `src: 'loMesb'` tag consistent with a campaign identifier used to correlate exfiltrated data across victims. The @woodpecker-web-shared/components scope/name has no legitimate reason to transmit installer identity to an anonymous webhook collector at install time, and the behavior fires automatically without user interaction. This is a recon beacon consistent with a dependency-confusion or typosquat lure.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for @woodpecker-web-shared/components (npm). Pin to a known-safe version or switch to an alternative.