MAL-2026-17185
Malicious code in shoplist-app (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (fdceadb01f08162934382b121e813236b86adc0d4d74b7b2f062c78e529c34f6) shoplist-app@99.99.99 is a dependency-confusion / typosquat beacon. preinstall.js is wired into every lifecycle hook (preinstall, install, postinstall, prepare, prepublish) and issues an HTTPS GET to the hardcoded endpoint https://eo8f3m3ho26a0nm.m.pipedream.net/, transmitting the installer's machine hostname via os.hostname() (smuggled into a `host` HTTP header) together with package identity in the query string. index.js — the package `main` — independently fires a second HTTPS GET to the same Pipedream collector at require/import time, carrying os.platform() and a `trigger=runtime` marker. The package ships no functional code beyond these beacons; its version (99.99.99) and description ("test") are consistent with a name-squat probe designed to identify which internal build hosts resolve the name shoplist-app. The exfiltrated data (hostname, OS platform, package-name confirmation) gives the operator of the Pipedream endpoint a map of environments where a shoplist-app dependency reference successfully resolves to this public package — the standard reconnaissance stage of a dependency-confusion attack.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for shoplist-app (npm). Pin to a known-safe version or switch to an alternative.