MAL-2026-12338

    Dashboard / Malicious Package / MAL-2026-12338

    MAL-2026-12338

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in alpha-helper (npm)

    Details: Source: amazon-inspector (9758eecca0cf755a3c7cc43115b413dfda31f149bbeed40cdfaeb5e46d739efb) The exported getPlugin in index.js issues an HTTPS request to a hardcoded bare-IP endpoint at 46.183.25.232:45000/icons/116 and passes the response field data.credits into a new Function(...) constructor with require, module, process, Buffer, and Promise bound into scope. Any consumer calling the exported function runs attacker-controlled JavaScript with full Node privileges. index.js also contains a decoy setDefaultModule that builds cdnjs-style font-awesome URLs across cloudflare/fastly/jsdelivr hostnames, which is not on the reachable code path. The package.json describes the module as a lightweight utility toolkit while the README describes an unrelated gamified trading system, and declared runtime dependencies include @primno/dpapi (Windows DPAPI unwrap), better-sqlite3, and node-machine-id, consistent with staging for browser-credential extraction.

    Affected packages

    Package

    Name: alpha-helper

    Purl: pkg:npm/alpha-helper

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.3.4
    MAL-2026-12338 | CVE-DB