MAL-2026-16478
Malicious code in event-hunter (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (f94b74862f327effaa43c1d01c4fd769626f73214d0706b80fef8b8a395cc3e8) On `npm install`, the declared postinstall hook runs `node index.js`, which reads `os.hostname()` and a timestamp, base64-encodes the JSON payload, and issues an HTTPS GET to `https://estimator-nemeses-unwatched.ngrok-free.dev/canary?d=<base64>`. The destination is a hardcoded ngrok tunnel unrelated to any registry or vendor infrastructure, and the beacon fires automatically without any caller action or opt-in. The package's own metadata describes it as a `Dependency Confusion to RCE` proof-of-concept, and the install-time callback carries the installer's internal hostname to an external third party.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for event-hunter (npm). Pin to a known-safe version or switch to an alternative.