MAL-2026-12518

    Dashboard / Malicious Package / MAL-2026-12518

    MAL-2026-12518

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in break-after (npm)

    Details: Source: amazon-inspector (80e06e591fd35c119051df59a1ed1771e74146adb37f3aef05367812412af1ad) The package's preinstall script runs automatically on `npm install` and collects os.hostname(), os.userInfo().username, process.cwd(), the configured npm registry, and a set of CI/repository environment variables, then sends the values as query-string parameters in an HTTP GET to the hardcoded bare-IP endpoint http://75.119.137.232:31337/depconfuse. The version number 9999.0.0 combined with the name of an existing public package and preinstall exfiltration of host, user, working-directory, and internal CI repository identifiers is the fingerprint of a dependency-confusion reconnaissance payload: it is designed to be pulled in by an internal build that resolves the higher version from the public registry, and to report back the identity of the victim organization and its private repository names.

    Affected packages

    Package

    Name: break-after

    Purl: pkg:npm/break-after

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    9999.0.0
    MAL-2026-12518 | CVE-DB