MAL-2026-10093

    Dashboard / Malicious Package / MAL-2026-10093

    MAL-2026-10093

    Published: 9 Jul 2026Last Modified: 9 Jul 2026

    Summary: Malicious code in @andrewstory18/is-real-odd (npm)

    Details: Source: amazon-inspector (0a6faaf0fbf39ed9ec8797c97cb8b2486be8b84eb46bfeabc3412a3eeded4aa1) @andrewstory18/is-real-odd impersonates the widely-used is-odd package by copying its README, author, and repository metadata verbatim, but ships an additional obfuscated payload (index.min.js) wired into package.json as a postinstall script. The payload uses an _0x string-array dispatcher to hide its behavior; once deobfuscated, it issues an http.request POST to the hardcoded bare IP 144.172.91.84 on port 3000 at path /hello. This fires automatically on npm install, establishing an attacker-controlled callback from any installer machine and enabling tracking of successful infections and staging of follow-on payloads. The destination is unrelated to the legitimate is-odd publisher (jonschlinkert) and is not a registry, CDN, or known SDK endpoint.

    Affected packages

    Package

    Name: @andrewstory18/is-real-odd

    Purl: pkg:npm/%40andrewstory18/is-real-odd

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    2.0.3
    MAL-2026-10093 | CVE-DB