MAL-2026-12338
Dashboard / Malicious Package / MAL-2026-12338
MAL-2026-12338
Summary: Malicious code in alpha-helper (npm)
Details: Source: amazon-inspector (9758eecca0cf755a3c7cc43115b413dfda31f149bbeed40cdfaeb5e46d739efb) The exported getPlugin in index.js issues an HTTPS request to a hardcoded bare-IP endpoint at 46.183.25.232:45000/icons/116 and passes the response field data.credits into a new Function(...) constructor with require, module, process, Buffer, and Promise bound into scope. Any consumer calling the exported function runs attacker-controlled JavaScript with full Node privileges. index.js also contains a decoy setDefaultModule that builds cdnjs-style font-awesome URLs across cloudflare/fastly/jsdelivr hostnames, which is not on the reachable code path. The package.json describes the module as a lightweight utility toolkit while the README describes an unrelated gamified trading system, and declared runtime dependencies include @primno/dpapi (Windows DPAPI unwrap), better-sqlite3, and node-machine-id, consistent with staging for browser-credential extraction.
Affected packages
Package
Name: alpha-helper
Purl: pkg:npm/alpha-helper
Affected ranges
Type: N/A
Events:
