VDB
Sign up

MAL-2026-16480

Malicious code in a-onesite (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (1b1ed6ca931448c083b5356eae6ad5af3cce9011d70fce4ce4ad427349991856) a-onesite@99.9.9 ships an empty index.js and no library functionality. Its package.json declares preinstall, preupdate, and test scripts that all invoke wget against http://eoy34oyrep9j5x8.m.pipedream.net with the installer's username ($(whoami)), current working directory ($(pwd)), and hostname ($(hostname)) as query parameters. The preinstall hook fires automatically on `npm install`, sending installer-identifying reconnaissance data over plaintext HTTP to a third-party collection endpoint unrelated to any advertised purpose. The version number (99.9.9) and empty code payload are consistent with a dependency-confusion reconnaissance beacon rather than a functional package.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/a-onesite

No fixed version published yet for a-onesite (npm). Pin to a known-safe version or switch to an alternative.

References