MAL-2026-12334

    Dashboard / Malicious Package / MAL-2026-12334

    MAL-2026-12334

    Published: 5 Aug 2026Last Modified: 6 Aug 2026

    Summary: Malicious code in ach-detail (npm)

    Details: Source: amazon-inspector (6c8ce91cbe1aaa587613795b1b82cc84384b499a29af4a18c0a820b77ea1d834) The npm package [email protected] ships a preinstall lifecycle script (scripts/preinstall.js) that runs automatically on `npm install`. The script collects the installer's hostname, package name and version, Node.js version, platform, timestamp, and a nonce, and POSTs the payload to a hardcoded remote endpoint at https://callback.kuldeep.io/beacon, with an HTTP fallback to the same host. The package is published to the public npm registry at version 99.0.1 — a version-inflation pattern consistent with dependency-confusion targeting of a private internal package of the same name. A log string in the script self-labels the behavior as an authorized bug-bounty PoC, but that label is author-controlled, does not change the observable behavior, and does not represent consent from any installer that resolves the package (accidentally or through dependency-confusion). Installer-side host identifiers leave the machine to a non-first-party endpoint on install.

    Affected packages

    Package

    Name: ach-detail

    Purl: pkg:npm/ach-detail

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    99.0.2
    99.0.1
    MAL-2026-12334 | CVE-DB