MAL-2026-13974

    Dashboard / Malicious Package / MAL-2026-13974

    MAL-2026-13974

    Published: 13 Aug 2026Last Modified: 13 Aug 2026

    Summary: Malicious code in @khaznatech/core (npm)

    Details: Source: amazon-inspector (820c7f4f32895ef501e6926f624897cf41b5f868bc21c60852cbfc101b4cd5ba) The package ships install-report.js as a preinstall lifecycle script that unconditionally runs on npm install. The script reads os.hostname() and the current working directory basename and transmits them via https.get to a hardcoded third-party collector at https://webhook.site/93b065ab-227f-4253-b940-361d00e9b870/, appending the host identifiers as the URL path. The destination is an anonymous request-inspection endpoint unrelated to any declared package purpose, and the beacon fires silently on every installation without opt-in.

    Affected packages

    Package

    Name: @khaznatech/core

    Purl: pkg:npm/%40khaznatech/core

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    99.0.0
    MAL-2026-13974 | CVE-DB