MAL-2026-16436
Malicious code in efhthrthrthregerht (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (4845639223c486cf2d33751ad950cea4c7f70401877929d25c36e7d07655d820) The package's postinstall hook runs index.js, which collects the installer's OS username, current working directory, hostname, and local IPv4 address and POSTs them as JSON to a hardcoded webhook.site collector URL (https://webhook.site/f9bff304-3053-4d54-be05-86537267514a) on npm install. The package name is a random keyboard-mash string with no documented purpose, and the only on-install behavior is the outbound beacon to an anonymous ephemeral webhook endpoint controlled by whoever created the webhook.site token.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for efhthrthrthregerht (npm). Pin to a known-safe version or switch to an alternative.