MAL-2026-10897

    Dashboard / Malicious Package / MAL-2026-10897

    MAL-2026-10897

    Published: 20 Jul 2026Last Modified: 1 Sept 2026Aliases: 
    GHSA-6p3c-6jvh-3pg8

    Summary: Malicious code in golan125-homepage-test (npm)

    Details: Source: amazon-inspector (705b0dc2e3b9aafb6d0e72ecb5ad51d873cd59104a045f74bb27161c87a24960) Package self-identifies as a security research test ('Security research test - do not install'). The package.json `homepage` field contains `javascript:alert(document.domain)`, which is an XSS probe targeting any registry or UI frontend that renders homepage values as clickable links without sanitization. The package has no lifecycle scripts (no preinstall/install/postinstall), no network I/O, and `index.js` exports an empty object — installing or requiring this package does not harm the installer's machine. The XSS probe targets registry web UI rendering, not developers who install the package.

    Affected packages

    Package

    Name: golan125-homepage-test

    Purl: pkg:npm/golan125-homepage-test

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0
    MAL-2026-10897 | CVE-DB