MAL-2026-11192

    Dashboard / Malicious Package / MAL-2026-11192

    MAL-2026-11192

    Published: 29 Jul 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in test2221 (npm)

    Details: Source: amazon-inspector (f6113dcb20ef051691e0cc0034132b94421604bd16a085229f75aae5c612a3d9) package.json declares preinstall and postinstall lifecycle scripts that run curl against http://54.37.234.136/voicemail over plain HTTP, sending the installer's username (whoami), hostname, working directory, and a timestamp as query-string parameters. Both hooks fire automatically on `npm install`, transmitting installer host identifiers to a hardcoded bare-IP endpoint with no relation to any documented package purpose. The behavior matches reconnaissance-beacon shape suitable for follow-on targeting of the installer's host. Source: ossf-package-analysis (178c9841a69c4a2de3ad248f8d4dbba8f004c8e8947a34f9e6ae12404183e6e2) The OpenSSF Package Analysis project identified 'test2221' @ 2.2.4 (npm) as malicious. It is considered malicious because: - The package executes one or more commands associated with malicious behavior.

    Affected packages

    Package

    Name: test2221

    Purl: pkg:npm/test2221

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    2.2.4
    2.2.3
    2.2.6
    MAL-2026-11192 | CVE-DB