MAL-2026-11158

    Dashboard / Malicious Package / MAL-2026-11158

    MAL-2026-11158

    Published: 28 Jul 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in blots (npm)

    Details: Source: amazon-inspector (847ba592915f4561a16225808a93d2428bc12305dc3df0bbf5316bf5a5bd7518) package.json defines preinstall and postinstall lifecycle scripts that unconditionally run curl against a hardcoded webhook.site endpoint, transmitting the installer's username (whoami), hostname, current working directory, and timestamp as query parameters. The endpoint is a third-party request-capture service controlled by the author (https://webhook.site/d80b4602-8a87-4693-8510-6ff77c62788e/blots). The package ships no other functionality tied to a documented purpose; the sole install-time effect is reconnaissance of the installer's host and identity to an attacker-controlled destination. Source: ossf-package-analysis (57066a6751b0444f7693ed35561fa24c16c649be8ce94c692b63f0470784866a) The OpenSSF Package Analysis project identified 'blots' @ 2.1.0 (npm) as malicious. It is considered malicious because: - The package executes one or more commands associated with malicious behavior.

    Affected packages

    Package

    Name: blots

    Purl: pkg:npm/blots

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    2.1.0
    2.1.1
    MAL-2026-11158 | CVE-DB