MAL-2026-10129
Dashboard / Malicious Package / MAL-2026-10129
MAL-2026-10129
Summary: Malicious code in rtc-integration-frontend-sdk (npm)
Details: Source: amazon-inspector (acfd49527fb8be1135feb424b68f6c46779ba146d8372d276eac1735770d6e5a) [email protected] registers a postinstall lifecycle hook ("postinstall": "node index.js") that fires automatically on npm install. index.js collects installer host reconnaissance — os.hostname(), userInfo().username, platform/arch, local network interface addresses, the public IP resolved via a call to https://api.ipify.org, the current working directory, and the package name — and POSTs the collected data to a hardcoded Discord webhook at discord.com/api/webhooks/. The package name and 99.9.0 version shape are consistent with a typosquat/version-bump lure; installing the package causes unconditional install-time exfiltration of host identifiers to an attacker-controlled endpoint.
Affected packages
Package
Name: rtc-integration-frontend-sdk
Purl: pkg:npm/rtc-integration-frontend-sdk
Affected ranges
Type: N/A
Events:
