MAL-2026-10620

    Dashboard / Malicious Package / MAL-2026-10620

    MAL-2026-10620

    Published: 14 Jul 2026Last Modified: 14 Jul 2026

    Summary: Malicious code in ahooks-3.7.8 (npm)

    Details: Source: amazon-inspector (c6816bbe8dc3e7d033a03452f7c1e8f873b97c158165faa863694ee13eb6dd61) Package published as `ahooks-3.7.8` at version `13.1.1` with empty author/description/license impersonates the legitimate `ahooks` React hooks library. `package.json` declares a `preinstall` hook that runs `node index.js`, which collects the installer's hostname, platform, architecture, username/uid/gid/shell, home directory, current working directory, and the output of `whoami` and `id`, and POSTs the JSON to the hardcoded Burp Collaborator subdomain `https://q7y246t0aca8jr8vfs8c900s4jaay1mq.oastify.com/detox56`. The script auto-executes on `npm install` without any user interaction.

    Affected packages

    Package

    Name: ahooks-3.7.8

    Purl: pkg:npm/ahooks-3.7.8

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    13.1.1
    MAL-2026-10620 | CVE-DB