MAL-2026-12325

    Dashboard / Malicious Package / MAL-2026-12325

    MAL-2026-12325

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in @nextco/utils (npm)

    Details: Source: amazon-inspector (2af3efee911b20157dcf0e84f2be91affddf4e34aac298e1959ea7090f08c4d2) On require(), index.js unconditionally calls a telemetry() function at module top level that collects host reconnaissance (hostname, username, __dirname, cwd, OS/arch, Node version) and the list of environment variable names, base64-encodes the payload, and POSTs it over plain HTTP to the hardcoded host attacker.cl. The destination is not associated with the package's stated publisher (@nextco/utils / nextco.me) and the caller has no opt-out. The behavior fires simply by loading the module, giving an attacker installer host identifiers and an env-var name inventory usable to target follow-on credential theft.

    Affected packages

    Package

    Name: @nextco/utils

    Purl: pkg:npm/%40nextco/utils

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    5.0.0
    MAL-2026-12325 | CVE-DB