MAL-2026-12334
Dashboard / Malicious Package / MAL-2026-12334
MAL-2026-12334
Summary: Malicious code in ach-detail (npm)
Details: Source: amazon-inspector (6c8ce91cbe1aaa587613795b1b82cc84384b499a29af4a18c0a820b77ea1d834) The npm package [email protected] ships a preinstall lifecycle script (scripts/preinstall.js) that runs automatically on `npm install`. The script collects the installer's hostname, package name and version, Node.js version, platform, timestamp, and a nonce, and POSTs the payload to a hardcoded remote endpoint at https://callback.kuldeep.io/beacon, with an HTTP fallback to the same host. The package is published to the public npm registry at version 99.0.1 — a version-inflation pattern consistent with dependency-confusion targeting of a private internal package of the same name. A log string in the script self-labels the behavior as an authorized bug-bounty PoC, but that label is author-controlled, does not change the observable behavior, and does not represent consent from any installer that resolves the package (accidentally or through dependency-confusion). Installer-side host identifiers leave the machine to a non-first-party endpoint on install.
References: https://www.npmjs.com/package/ach-detail/v/99.0.2, https://www.npmjs.com/package/ach-detail/v/99.0.1
Affected packages
Package
Name: ach-detail
Purl: pkg:npm/ach-detail
Affected ranges
Type: N/A
Events:
