MAL-2026-14034
Dashboard / Malicious Package / MAL-2026-14034
MAL-2026-14034
Summary: Malicious code in notafollower1 (npm)
Details: Source: amazon-inspector (7c74ec5369dac32115a9f5f257f512fa0a48d2e914b1f18c5178992b0a1604f9) package.json declares a postinstall script that automatically runs on npm install and fetches AWS ECS container task metadata via the ECS_CONTAINER_METADATA_URI_V4 endpoint (task ARN, container names, image names), then POSTs the collected data to a hardcoded ngrok tunnel at https://mourner-slot-explicit.ngrok-free.dev using curl. The postinstall also inspects the container image name for substrings matching known security research operators (twbray, packagehound, wiz, oss-dynamic) and labels the payload accordingly, indicating deliberate sandbox and analyst fingerprinting. The destination is an anonymous ngrok tunnel unrelated to any legitimate publisher infrastructure, and the collected data reveals installer-side CI/build/container environment details to a third party.
References: https://www.npmjs.com/package/notafollower1/v/1.0.1, https://www.npmjs.com/package/notafollower1/v/1.0.13, https://www.npmjs.com/package/notafollower1/v/1.0.3, https://www.npmjs.com/package/notafollower1/v/1.0.8, https://www.npmjs.com/package/notafollower1/v/1.0.7, https://www.npmjs.com/package/notafollower1/v/1.0.5, https://www.npmjs.com/package/notafollower1/v/1.0.11, https://www.npmjs.com/package/notafollower1/v/1.0.12, https://www.npmjs.com/package/notafollower1/v/1.0.9, https://www.npmjs.com/package/notafollower1/v/1.0.4, https://www.npmjs.com/package/notafollower1/v/1.0.6, https://www.npmjs.com/package/notafollower1/v/1.0.10, https://www.npmjs.com/package/notafollower1/v/1.0.2, https://www.npmjs.com/package/notafollower1/v/1.0.0
Affected packages
Package
Name: notafollower1
Purl: pkg:npm/notafollower1
Affected ranges
Type: N/A
Events:
