MAL-2026-10530

    Dashboard / Malicious Package / MAL-2026-10530

    MAL-2026-10530

    Published: 14 Jul 2026Last Modified: 14 Jul 2026

    Summary: Malicious code in cbr-internal-utils (npm)

    Details: Source: amazon-inspector (fa96f42fade399b9e73756e2abd62eafbfa11e2eb02fe1055d9c7e025fba4ab7) On module load, the package's main entrypoint shells out via child_process.exec to run `cat /etc/passwd` and prints the contents to stdout. This fires unconditionally when any consumer `require()`s the package — no user action or configuration is needed. The package has an internal-sounding name and empty author/description metadata, consistent with a dependency-confusion probe or reconnaissance payload rather than a legitimate library. Reading /etc/passwd serves no library purpose and enumerates local user accounts on the installer's host.

    Affected packages

    Package

    Name: cbr-internal-utils

    Purl: pkg:npm/cbr-internal-utils

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    2.2.2