MAL-2026-13989
Dashboard / Malicious Package / MAL-2026-13989
MAL-2026-13989
Summary: Malicious code in @secauditb20y/sec-test-r3b (npm)
Details: Source: amazon-inspector (df7034b94531c8be5e9141c7a5cf73f552486c1b307672346a0e646e60207b7c) package.json declares a postinstall script that runs `node -e` to invoke fs.writeFileSync, creating /tmp/PWN_R3REAL/FIRED on the installer's machine when the package is installed. The package's main module only exports the literal value 42 and ships no native build or legitimate reason for install-time execution; the postinstall exists solely to demonstrate arbitrary code execution on the installer host at `npm install` time. The behavior fires automatically on default install and writes to a path outside the package directory, matching the shape of a proof-of-execution beacon. The package name and description self-identify as an authorized security test, but self-labeling is not a mitigation and the code path is functionally identical to a dropper marker.
Affected packages
Package
Name: @secauditb20y/sec-test-r3b
Purl: pkg:npm/%40secauditb20y/sec-test-r3b
Affected ranges
Type: N/A
Events:
