MAL-2026-12353

    Dashboard / Malicious Package / MAL-2026-12353

    MAL-2026-12353

    Published: 5 Aug 2026Last Modified: 1 Sept 2026

    Summary: Malicious code in clover-codelab-remote-pay-cloud (npm)

    Details: Source: amazon-inspector (071fbdd6b5ca7cbb0fc696f5abf7a47be3783dd970ca5594cb415e67579f2b15) The package declares a postinstall hook that runs index.js on npm install. index.js collects the OS username, current working directory, hostname, and non-internal IPv4 address via os.userInfo(), process.cwd(), os.hostname(), and os.networkInterfaces(), then POSTs the values as JSON over https to a hardcoded webhook.site collector at https://webhook.site/9aa13631-fbb0-4b6b-a256-27d1672f767c. The package name resembles Clover's remote-pay-cloud SDK and the version is set to 99.9.9, a dependency-confusion shape intended to override an internal package during resolution. The package provides no functionality matching its name — its only install-time effect is the exfiltration beacon.

    Affected packages

    Package

    Name: clover-codelab-remote-pay-cloud

    Purl: pkg:npm/clover-codelab-remote-pay-cloud

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    99.9.9
    MAL-2026-12353 | CVE-DB