MAL-2026-12435

    Dashboard / Malicious Package / MAL-2026-12435

    MAL-2026-12435

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in sc-geeksquad-core (npm)

    Details: Source: amazon-inspector (2fd2458d8a5843f57187868a2c244a376dd3d2daef420d3c564c775ef6a2782a) [email protected] declares a preinstall script `node callback.js` that runs automatically on `npm install`. The script collects the installer's hostname (`os.hostname()`), OS username (`os.userInfo().username`), current working directory (`process.cwd()`), configured npm registry (`npm_config_registry`), and a set of CI repository-slug environment variables (GITHUB_REPOSITORY, CI_PROJECT_PATH, BUILD_REPOSITORY_NAME, BITBUCKET_REPO_FULL_NAME, TRAVIS_REPO_SLUG, DRONE_REPO, BUILDKITE_PIPELINE_SLUG, CIRCLE_PROJECT_REPONAME, JOB_NAME), then sends them via HTTP GET to the hardcoded bare-IP endpoint `http://75.119.137.232:31337/depconfuse` as query parameters. The placeholder version `9999.0.0` combined with a generic scoped-sounding name is the canonical dependency-confusion reconnaissance shape: the package is published to public npm to intercept internal-package name resolution and beacon back which private-namespace builds are vulnerable to substitution.

    Affected packages

    Package

    Name: sc-geeksquad-core

    Purl: pkg:npm/sc-geeksquad-core

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    9999.0.0