VDB
Sign up

MAL-2026-16434

Malicious code in catplatebarcodeparser (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (189a06b0d55d6dab795bcb9ba3a97aa855b2556a54e85e15adc9f5bf20399976) catplatebarcodeparser@99.2.1 declares preinstall and postinstall lifecycle scripts that execute scripts/run.js on `npm install`. That script reads os.userInfo().username and os.hostname() and POSTs them to a hardcoded out-of-band collector at https://webhook.site/40e9b065-efd7-43a5-916f-3d52281f42b6, and additionally issues a DNS lookup against 40e9b065-efd7-43a5-916f-3d52281f42b6.dnshook.site as a canary. The version number (99.2.1) and package name pattern are consistent with a dependency-confusion lure intended to win resolution against an internal package of the same name; installing the lure automatically leaks installer identity to an author-controlled endpoint.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/catplatebarcodeparser

No fixed version published yet for catplatebarcodeparser (npm). Pin to a known-safe version or switch to an alternative.

References