MAL-2026-13280
Dashboard / Malicious Package / MAL-2026-13280
MAL-2026-13280
Summary: Malicious code in docker-api-client (npm)
Details: Source: amazon-inspector (f02e61d324161238593fb7e59dc907f183bf885a908354fed1eba0662906947b) [email protected] is a typosquat of dockerode. On require(), index.js collects hostname, username, homedir, platform, cwd, and the entire process.env object, JSON-serializes and base64-encodes the payload, and sends it via HTTPS GET to api.telegram.org bot sendMessage with a hardcoded bot token and chat_id; a tmp flag file marks first-run. The environment dump routinely contains CI/CD tokens, cloud credentials (AWS_*, GITHUB_TOKEN, NPM_TOKEN), and database secrets, so any process that imports this package leaks its full credential-bearing environment to an attacker-controlled Telegram chat. The module's fallback exports expose wallet primitives (createWallet, signTransaction, generateMnemonic) that do not match the advertised Docker API purpose, confirming the package as a cover-story lure rather than a Docker client.
Affected packages
Package
Name: docker-api-client
Purl: pkg:npm/docker-api-client
Affected ranges
Type: N/A
Events:
