MAL-2026-10893
Dashboard / Malicious Package / MAL-2026-10893
MAL-2026-10893
Summary: Malicious code in ecto-cargo-wk1tm59a (npm)
Details: Source: amazon-inspector (ee496f01ecebc77637213e597ba523c8cccda7efcd65e7ad2e700d804553dd29) Package [email protected] exhibits several contextual red flags worth human review: a randomized-suffix name pattern (`-wk1tm59a`) typical of disposable/throwaway publishes, an inflated `99.0.0` version typical of dependency-confusion / proof-of-concept publishes, and only 3 files in the tarball. Automated content inspection of the package's code did not produce a usable trace, but the content was non-trivial enough that an automated description could not be produced. No specific attacker domain, exfiltration endpoint, or install-time fetch-and-execute behavior has been concretely identified from the available evidence, so a public block verdict is not justified, but the combination of disposable-name shape, `99.0.0` version inflation, and untraced contents warrants human inspection before this package is trusted.
References: https://www.npmjs.com/package/ecto-cargo-wk1tm59a/v/99.0.0, https://github.com/advisories/GHSA-wx6c-2wgg-hcwq
Affected packages
Package
Name: ecto-cargo-wk1tm59a
Purl: pkg:npm/ecto-cargo-wk1tm59a
Affected ranges
Type: N/A
Events:
