MAL-2026-13968

    Dashboard / Malicious Package / MAL-2026-13968

    MAL-2026-13968

    Published: 13 Aug 2026Last Modified: 13 Aug 2026

    Summary: Malicious code in @hzero-front-ui/cfg (npm)

    Details: Source: amazon-inspector (d280060b3d704c67c4a2cc853fde425220e6a3606f71269daa8a9b3e74052f6d) package.json declares preinstall and install lifecycle scripts that, on npm install, collect whoami, hostname, current working directory, and npm_package_name, base64-encode the concatenation, and transmit it to subdomains of callback.m0chan.co.uk via both an HTTPS GET (curl to https://<sub>.callback.m0chan.co.uk/<b64>) and a DNS lookup (nslookup against <pkgdns>.<sub>.callback.m0chan.co.uk). The 99.99.99 version and scoped name pattern are consistent with a dependency-confusion beacon targeting an internal @hzero-front-ui scope.

    Affected packages

    Package

    Name: @hzero-front-ui/cfg

    Purl: pkg:npm/%40hzero-front-ui/cfg

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    99.99.99
    MAL-2026-13968 | CVE-DB