MAL-2026-14117

    Dashboard / Malicious Package / MAL-2026-14117

    MAL-2026-14117

    Published: 18 Aug 2026Last Modified: 18 Aug 2026

    Summary: Malicious code in bcc-design (npm)

    Details: Source: amazon-inspector (d36ad8d761b526fd22c960a4d7ffb2a11134996e031535e56865e91135b3be80) [email protected] is a dependency-confusion beacon package published at an implausibly high version to shadow an internal package name. On npm install, its postinstall lifecycle script executes notify.js, which reads os.hostname() and issues an HTTP GET to the hardcoded bare-IP endpoint http://91.201.215.48:8000/npm-poc-bcc carrying the installer's hostname, the package name, and a timestamp as query parameters. A second network reference to webhook.site is present in the same file. The package provides no legitimate library functionality; its only install-time effect is transmitting installer identity to an attacker-controlled destination.

    Affected packages

    Package

    Name: bcc-design

    Purl: pkg:npm/bcc-design

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    9999.0.0
    MAL-2026-14117 | CVE-DB