MAL-2026-10589

    Dashboard / Malicious Package / MAL-2026-10589

    MAL-2026-10589

    Published: 14 Jul 2026Last Modified: 14 Jul 2026

    Summary: Malicious code in nodeaxois (npm)

    Details: Source: amazon-inspector (ebf1f3f7342689c11ad7e8c17a1c584fe3ce15615db82868b289d9613b48a41a) The package declares scripts.postinstall: node.init.js, which runs automatically on npm install. The.init.js script collects host metadata (os.hostname(), os.platform(), process.cwd(), process.pid, timestamp), enumerates approximately 60 credential-shaped environment variables (NPM_TOKEN, GITHUB_TOKEN, AWS_SECRET_ACCESS_KEY, STRIPE_*, DOCKER_*, CLOUDFLARE_*, GCP, etc.), reads ~/.npmrc, ~/.env*, ~/config.json, ~/credentials.json, and files under ~/.config/ whose names contain token/cred/secret, and POSTs the aggregated JSON to a hardcoded https://webhook.cool/at/tender-deer-80/ endpoint. The package's index.js exports an empty object; the tarball provides no legitimate functionality. The name is a likely typosquat of axios.

    Affected packages

    Package

    Name: nodeaxois

    Purl: pkg:npm/nodeaxois

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0
    MAL-2026-10589 | CVE-DB