MAL-2026-13725

    Dashboard / Malicious Package / MAL-2026-13725

    MAL-2026-13725

    Published: 10 Aug 2026Last Modified: 11 Aug 2026Aliases: 
    GHSA-72h3-pwwh-68cx

    Summary: Malicious code in spoint (npm)

    Details: Source: amazon-inspector (4c32e6b328bf731b6269e720e0fda2dec5264452ef04d406fde5296413424525) Static keyword matches fired on the co-occurrence of tokens like 'curl', 'ping', 'POST', and 'GET' inside SDK/orchestrator source files (bin/room-orchestrator-boot.js, src/sdk/RoomOrchestrator.js, src/sdk/ServerAPI.js, src/sharding/RegionRouter.js). These are consistent with an orchestrator/routing SDK that performs latency probes and HTTP requests against its own service endpoints — the shape of a room/region networking client, not of an exfiltration primitive. No specific installer-side secret is shown being read (no ~/.aws, ~/.ssh, ~/.npmrc, env-var scraping, browser profile access), no hardcoded attacker C2 destination is named in evidence, and no lifecycle hook or top-level require-time execution path invoking these calls is demonstrated. Keyword co-occurrence in networking code is the shared shape of legitimate HTTP clients and cannot by itself establish exfiltration intent. Source: ghsa-malware (4952c46b3a196baaec2d02092303fb499978b121dd6dac73c2f98e193985690c) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

    Affected packages

    Package

    Name: spoint

    Purl: pkg:npm/spoint

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.1.700
    0.1.699
    0.1.698
    0.1.697
    0.1.696
    0.1.695
    MAL-2026-13725 | CVE-DB