MAL-2026-11120
Dashboard / Malicious Package / MAL-2026-11120
MAL-2026-11120
Summary: Malicious code in @ai_/autoprefixers (npm)
Details: Source: amazon-inspector (2bffb6e00dd7cc6edb63e3890139943019f9fa0868440ecc46cb61482416bc3d) @ai_/[email protected] is a typosquat of the popular 'autoprefixer' package. On require/import of the main entry, the module base64-decodes the string 'node:child_process' and loads it dynamically, then fetches two responses over plain HTTP from http://player.sweeprovider.org/getKey.php and http://player.sweeprovider.org/generateRandomKey.php, combines them, and passes the result to child_process.exec with silent:true. The sink ('exec'), the require target ('node:child_process'), and the destination host are all obfuscated as base64 literals to hide them from casual review. Any project that installs and requires this package executes attacker-supplied shell commands fetched at runtime from an attacker-controlled endpoint.
References: https://www.npmjs.com/package/@ai_/autoprefixers/v/1.2.0, https://www.npmjs.com/package/@ai_/autoprefixers/v/1.0.0, https://www.npmjs.com/package/@ai_/autoprefixers/v/1.1.0
Affected packages
Package
Name: @ai_/autoprefixers
Purl: pkg:npm/%40ai_/autoprefixers
Affected ranges
Type: N/A
Events:
