MAL-2026-10678

    Dashboard / Malicious Package / MAL-2026-10678

    MAL-2026-10678

    Published: 15 Jul 2026Last Modified: 15 Jul 2026

    Summary: Malicious code in ls-env-config (npm)

    Details: Source: amazon-inspector (db44619df34ccbffa5747f17c8135602583a781ec01f8d3c03e0f828157e944c) Package declares a `preinstall` script (`node./index.js`) that fires automatically on `npm install`. The executed `index.js` issues an HTTP GET to a Burp-Collaborator-style subdomain at `85324cf9ac5145428803ea[...].collaborator.zivyelab.com/hello01?test=01`. This confirms code execution on the installer's machine and a DNS/HTTP callback to a non-first-party host on every install, leaking host and network reachability information. The pattern is consistent with a dependency-confusion probe; regardless of stated intent, it executes on any installer and beacons to a third-party collaborator endpoint.

    Affected packages

    Package

    Name: ls-env-config

    Purl: pkg:npm/ls-env-config

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.5
    MAL-2026-10678 | CVE-DB