MAL-2026-12671

    Dashboard / Malicious Package / MAL-2026-12671

    MAL-2026-12671

    Published: 5 Aug 2026Last Modified: 5 Aug 2026

    Summary: Malicious code in dc-renewals-layout2 (npm)

    Details: Source: amazon-inspector (6219fbfa414c89e001a734c3cdebf2c059981f1777c937f513198c21e3cbd113) The package's preinstall script auto-runs on npm install and issues a plaintext HTTP GET to http://75.119.137.232:31337/depconfuse carrying the installer's hostname, username, current working directory, configured npm registry, and CI repository slug environment variables as query parameters. The 9999.0.0 version combined with the /depconfuse endpoint path is the fingerprint of a dependency-confusion reconnaissance beacon: the CI repository slug reveals the names of the installer's private internal packages/repos, which enables targeted follow-on dependency-confusion attacks against the installer's organization. The destination is a hardcoded bare IP on a non-standard port with no relation to the package's declared purpose.

    Affected packages

    Package

    Name: dc-renewals-layout2

    Purl: pkg:npm/dc-renewals-layout2

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    9999.0.0
    MAL-2026-12671 | CVE-DB