MAL-2026-16465
Malicious code in helpersutils-dev-tools (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (85b7208dea3cf1742ac01332c17db9df968fd4a105fbccaf0b5388162b0f3673) The package presents itself as 'Development utility helpers' but its main module executes an IIFE at require-time that issues an Image request to http://5.189.173.113:8899/csp-edu with document.domain appended as a query parameter. A sibling file bypass.js contains an equivalent beacon to http://5.189.173.113:8899/csp. Both destinations are a hardcoded bare IP over plain HTTP, unrelated to any advertised functionality, and receive host-context data (the consuming page's domain) whenever the module is loaded.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for helpersutils-dev-tools (npm). Pin to a known-safe version or switch to an alternative.