MAL-2026-12353
Dashboard / Malicious Package / MAL-2026-12353
MAL-2026-12353
Summary: Malicious code in clover-codelab-remote-pay-cloud (npm)
Details: Source: amazon-inspector (071fbdd6b5ca7cbb0fc696f5abf7a47be3783dd970ca5594cb415e67579f2b15) The package declares a postinstall hook that runs index.js on npm install. index.js collects the OS username, current working directory, hostname, and non-internal IPv4 address via os.userInfo(), process.cwd(), os.hostname(), and os.networkInterfaces(), then POSTs the values as JSON over https to a hardcoded webhook.site collector at https://webhook.site/9aa13631-fbb0-4b6b-a256-27d1672f767c. The package name resembles Clover's remote-pay-cloud SDK and the version is set to 99.9.9, a dependency-confusion shape intended to override an internal package during resolution. The package provides no functionality matching its name — its only install-time effect is the exfiltration beacon.
Affected packages
Package
Name: clover-codelab-remote-pay-cloud
Purl: pkg:npm/clover-codelab-remote-pay-cloud
Affected ranges
Type: N/A
Events:
