MAL-2026-10551

    Dashboard / Malicious Package / MAL-2026-10551

    MAL-2026-10551

    Published: 14 Jul 2026Last Modified: 15 Jul 2026

    Summary: Malicious code in elsisi-cli (npm)

    Details: Source: amazon-inspector (4deec3de3ca46a57023580a81da870e3ce444a691ad6f42f5217abe206ef448a) package.json declares preinstall and postinstall lifecycle scripts that invoke wget against https://webhook.site/d5968c3d-d0d7-46c4-9305-a726b24fce9c/, passing the installer's current working directory and hostname as query-string parameters ($(pwd), $(hostname)). Both beacons fire automatically on `npm install`. The tarball ships only package.json (371 bytes); the declared main entry index.js is absent and no source, README, or functionality accompanies the lifecycle hooks, so the package's only effect on install is the outbound beacon to the attacker-controlled webhook.site collector.

    Affected packages

    Package

    Name: elsisi-cli

    Purl: pkg:npm/elsisi-cli

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    9.9.9
    MAL-2026-10551 | CVE-DB