MAL-2026-11120

    Dashboard / Malicious Package / MAL-2026-11120

    MAL-2026-11120

    Published: 28 Jul 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in @ai_/autoprefixers (npm)

    Details: Source: amazon-inspector (2bffb6e00dd7cc6edb63e3890139943019f9fa0868440ecc46cb61482416bc3d) @ai_/[email protected] is a typosquat of the popular 'autoprefixer' package. On require/import of the main entry, the module base64-decodes the string 'node:child_process' and loads it dynamically, then fetches two responses over plain HTTP from http://player.sweeprovider.org/getKey.php and http://player.sweeprovider.org/generateRandomKey.php, combines them, and passes the result to child_process.exec with silent:true. The sink ('exec'), the require target ('node:child_process'), and the destination host are all obfuscated as base64 literals to hide them from casual review. Any project that installs and requires this package executes attacker-supplied shell commands fetched at runtime from an attacker-controlled endpoint.

    Affected packages

    Package

    Name: @ai_/autoprefixers

    Purl: pkg:npm/%40ai_/autoprefixers

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.2.0