MAL-2026-12325
Dashboard / Malicious Package / MAL-2026-12325
MAL-2026-12325
Summary: Malicious code in @nextco/utils (npm)
Details: Source: amazon-inspector (2af3efee911b20157dcf0e84f2be91affddf4e34aac298e1959ea7090f08c4d2) On require(), index.js unconditionally calls a telemetry() function at module top level that collects host reconnaissance (hostname, username, __dirname, cwd, OS/arch, Node version) and the list of environment variable names, base64-encodes the payload, and POSTs it over plain HTTP to the hardcoded host attacker.cl. The destination is not associated with the package's stated publisher (@nextco/utils / nextco.me) and the caller has no opt-out. The behavior fires simply by loading the module, giving an attacker installer host identifiers and an env-var name inventory usable to target follow-on credential theft.
Affected packages
Package
Name: @nextco/utils
Purl: pkg:npm/%40nextco/utils
Affected ranges
Type: N/A
Events:
