MAL-2026-10444
Dashboard / Malicious Package / MAL-2026-10444
MAL-2026-10444
Summary: Malicious code in markable-table (npm)
Details: Source: amazon-inspector (fd358271f202636f12507f09da4e8f00c900ba46c9dca25a5a0526d35b75bf1d) [email protected] declares scripts.preinstall = 'node index.d.js'. index.d.js base64-decodes an embedded payload and invokes it through an identifier reconstructed from a char-code array ([101,118,97,108] = 'eval'), hiding the 'eval' token from plain-text scanners. The decoded payload fetches JavaScript from https://everydaynodechecker-39143n.vercel.app/api/key?mem=root0 and eval()s the response body at npm install time, giving the operator of that endpoint arbitrary code execution on any machine that runs `npm install`. The remote-fetch-and-eval, the obfuscation of both the 'eval' identifier and the destination URL, the non-first-party Vercel host, and the mismatch with the package's advertised markdown-table purpose (and typosquat of the popular 'markdown-table' package) together match the install-time-RCE dropper pattern. Source: ghsa-malware (d4db694f1a9db0f84f99ffe21a31c0a526f67dafe412b53dcee0c75eb79678e1) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
References: https://www.npmjs.com/package/markable-table/v/3.1.2, https://www.npmjs.com/package/markable-table/v/3.1.4, https://www.npmjs.com/package/markable-table/v/3.1.3, https://www.npmjs.com/package/markable-table/v/3.1.8, https://www.npmjs.com/package/markable-table/v/3.1.6, https://www.npmjs.com/package/markable-table/v/3.1.7, https://www.npmjs.com/package/markable-table/v/3.1.5, https://github.com/advisories/GHSA-qc34-pqm6-35rf, https://www.npmjs.com/package/markable-table/v/3.1.1, https://www.npmjs.com/package/markable-table/v/3.1.0
Affected packages
Package
Name: markable-table
Purl: pkg:npm/markable-table
Affected ranges
Type: SEMVER
Events:
