MAL-2026-17215
Malicious code in eslint-plugin-skywagon-web (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (3c5d134d2e79b24ed65d2998520db05b5cc86b251ae579a6d8cec6d8fe02340f) eslint-plugin-skywagon-web@100.0.0 ships an index.js that is executed via a preinstall lifecycle script on `npm install`. The script collects installer-side identifiers — os.hostname(), os.userInfo().username, os.homedir(), process.cwd(), dns.getServers(), and the contents of the package's package.json — and POSTs them over HTTPS to the hardcoded external collector eo1blcdjptwydyq.m.pipedream.net. A source comment ("replace burpcollaborator.net with Interactsh or pipedream") shows the file is a dependency-confusion exfiltration template repurposed as a live payload. The implausibly high version number (100.0.0) is consistent with a dependency-confusion lure intended to override an internal package of the same name during resolution.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for eslint-plugin-skywagon-web (npm). Pin to a known-safe version or switch to an alternative.