MAL-2026-12496

    Dashboard / Malicious Package / MAL-2026-12496

    MAL-2026-12496

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in voicemail (npm)

    Details: Source: amazon-inspector (568a31285f414d8125b5749bc8e070157ffd403ce46e46da637cc1452f99d19f) package.json declares both preinstall and postinstall lifecycle scripts that invoke curl against a hardcoded webhook.site endpoint (https://webhook.site/d80b4602-8a87-4693-8510-6ff77c62788e/blots) with query parameters carrying the installer's username ($(whoami)), hostname ($(hostname)), current working directory ($PWD), and a timestamp. The beacon fires automatically on `npm install` without user consent, sending host and identity reconnaissance to an attacker-controlled collector. The package provides no legitimate functionality corresponding to this network activity.

    Affected packages

    Package

    Name: voicemail

    Purl: pkg:npm/voicemail

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.1
    1.0.2
    MAL-2026-12496 | CVE-DB