MAL-2026-10393
Dashboard / Malicious Package / MAL-2026-10393
MAL-2026-10393
Summary: Malicious code in tipsen-poc-again (npm)
Details: Source: amazon-inspector (c0977477bc81c656f52fb981657983580b411dda6d2c6766ba4d6a35fe4ae970) package.json declares its sole runtime dependency `safe-chain-test` as an HTTPS tarball URL pointing at a `trycloudflare.com` quick-tunnel host (`https://dominant-vary-ran-americas.trycloudflare.com/safe-chain-test-1.0.0.tgz`). trycloudflare quick-tunnel hosts are anonymous, ephemeral, publisher-unattributable, and fully mutable — the operator can serve arbitrary bytes to any installer at any time, and the bytes are not subject to npm registry scanning. On `npm install`, npm fetches this tarball and installs it into the dependency tree; whatever lifecycle scripts or top-level code the current tarball contains will execute on the installer's machine. This is a transitive code-delivery channel routed through an attacker-controlled hop that bypasses registry integrity controls. Source: ghsa-malware (326b0265c949c38b2bc44d359703d628ebb46fd827789d7b0d0729a160a9caff) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
References: https://github.com/advisories/GHSA-q256-mmcv-pqmq, https://www.npmjs.com/package/tipsen-poc-again/v/1.0.0
Affected packages
Package
Name: tipsen-poc-again
Purl: pkg:npm/tipsen-poc-again
Affected ranges
Type: SEMVER
Events:
