MAL-2026-10897
Dashboard / Malicious Package / MAL-2026-10897
MAL-2026-10897
Summary: Malicious code in golan125-homepage-test (npm)
Details: Source: amazon-inspector (705b0dc2e3b9aafb6d0e72ecb5ad51d873cd59104a045f74bb27161c87a24960) Package self-identifies as a security research test ('Security research test - do not install'). The package.json `homepage` field contains `javascript:alert(document.domain)`, which is an XSS probe targeting any registry or UI frontend that renders homepage values as clickable links without sanitization. The package has no lifecycle scripts (no preinstall/install/postinstall), no network I/O, and `index.js` exports an empty object — installing or requiring this package does not harm the installer's machine. The XSS probe targets registry web UI rendering, not developers who install the package.
References: https://www.npmjs.com/package/golan125-homepage-test/v/1.0.0, https://github.com/advisories/GHSA-6p3c-6jvh-3pg8
Affected packages
Package
Name: golan125-homepage-test
Purl: pkg:npm/golan125-homepage-test
Affected ranges
Type: N/A
Events:
