MAL-2026-10675

    Dashboard / Malicious Package / MAL-2026-10675

    MAL-2026-10675

    Published: 15 Jul 2026Last Modified: 15 Jul 2026

    Summary: Malicious code in ac-raf-emitter (npm)

    Details: Source: amazon-inspector (4a9d9e454c08fdafa531ee74a3bc52513d5bc39413810db4a6371494872984f8) package.json declares a preinstall lifecycle script that runs `curl -X POST` against a hardcoded webhook.site collector URL (https://webhook.site/54919426-084d-4288-8f80-e36ae5c76e32), passing the installer's hostname and a timestamp as query parameters. The exfiltration fires automatically on `npm install` before any consumer code runs. The destination is an anonymous, author-controlled request-inspection endpoint with no legitimate role in the package's advertised functionality.

    Affected packages

    Package

    Name: ac-raf-emitter

    Purl: pkg:npm/ac-raf-emitter

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    3.0.1
    MAL-2026-10675 | CVE-DB