MAL-2026-14016

    Dashboard / Malicious Package / MAL-2026-14016

    MAL-2026-14016

    Published: 13 Aug 2026Last Modified: 13 Aug 2026

    Summary: Malicious code in preinstall-hook-webhook-callback-demo (npm)

    Details: Source: amazon-inspector (d6e707d55368c2628038e0efaac35629fba6dbd520e66a7e29f9c6a86c69b2e1) package.json declares a preinstall lifecycle script that contacts webhook.site, an ephemeral request-capture service commonly used as an attacker-controlled exfiltration sink. The hook fires automatically on `npm install` before any user interaction, and webhook.site is not a first-party or documented destination for any legitimate build or runtime purpose of this package. The combination of an auto-executing preinstall script wired to an out-of-band capture endpoint is the shape of installer-side data exfiltration / callback beaconing at install time.

    Affected packages

    Package

    Name: preinstall-hook-webhook-callback-demo

    Purl: pkg:npm/preinstall-hook-webhook-callback-demo

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.1
    1.0.0
    MAL-2026-14016 | CVE-DB