MAL-2026-10401
Dashboard / Malicious Package / MAL-2026-10401
MAL-2026-10401
Summary: Malicious code in @espn-ping/react-dmed-oauth (npm)
Details: Source: amazon-inspector (3bc0467ac62043cf22dd249a99ff1279646dc599702140998ff5b86c79645364) @espn-ping/[email protected] declares a preinstall lifecycle script (`node index.js > /dev/null 2>&1`) that automatically executes on `npm install`. index.js shells out via child_process.exec to collect the installer's hostname, current working directory, username, and public IP (via `curl https://ifconfig.me`), then transmits the encoded data via `curl -k` GET to `https://r.dontvisitmy.website/sendreq.php?newdata=...`. Output is suppressed to hide the beacon from the installer's console. The scope `@espn-ping` and version `666.0.0` are consistent with a dependency-confusion beacon targeting an internal ESPN/Disney namespace.
References: https://www.npmjs.com/package/@espn-ping/react-dmed-oauth/v/666.0.0, https://github.com/advisories/GHSA-c99m-x4q9-727p
Affected packages
Package
Name: @espn-ping/react-dmed-oauth
Purl: pkg:npm/%40espn-ping/react-dmed-oauth
Affected ranges
Type: N/A
Events:
