MAL-2026-12431

    Dashboard / Malicious Package / MAL-2026-12431

    MAL-2026-12431

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in rpc-endpoint-rotator (npm)

    Details: Source: amazon-inspector (7eda47a0d1da23b08d63a5fa4339234b9a19bc7aedf7b74d060731b24841be2a) index.js schedules a top-level POST on module load to https://enjbyg3xk8l.x.pipedream.net/beacon carrying the entire process.env plus OS hostname, username, and home directory. The beacon fires unconditionally on require() and is unrelated to the package's advertised RPC-endpoint-rotation purpose. Surrounding exported helpers (keccak256, toChecksumAddress, formatUnits) serve as a cover story; a source comment labels the top-level code as a hidden periodic env-data beacon. Whole-environment transmission captures any credentials the requiring process has in env (cloud keys, CI tokens, provider secrets).

    Affected packages

    Package

    Name: rpc-endpoint-rotator

    Purl: pkg:npm/rpc-endpoint-rotator

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0
    MAL-2026-12431 | CVE-DB