MAL-2026-13743

    Dashboard / Malicious Package / MAL-2026-13743

    MAL-2026-13743

    Published: 11 Aug 2026Last Modified: 11 Aug 2026

    Summary: Malicious code in whs4_ued (npm)

    Details: Source: amazon-inspector (6be723a2156cdb77cc97a0afb9ee15e4d50928a1924cd6cde69bcaacf2707a8b) On npm install, the package's postinstall hook runs `node index.js`, which POSTs installer host information — the absolute path of the package file (leaking the OS username and home directory layout), Node.js version, platform, and architecture — to a hardcoded Discord webhook at discord.com/api/webhooks/1530599209269465319/. The webhook token is assembled via string concatenation at the call site to evade naive string matching. The destination is attacker-controlled and unrelated to the package's stated educational typo-catcher purpose, and there is no consent gate.

    Affected packages

    Package

    Name: whs4_ued

    Purl: pkg:npm/whs4_ued

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0