MAL-2026-14119

    Dashboard / Malicious Package / MAL-2026-14119

    MAL-2026-14119

    Published: 18 Aug 2026Last Modified: 18 Aug 2026

    Summary: Malicious code in bcc-design-icons (npm)

    Details: Source: amazon-inspector (8f25ef58a44d6da495f8f9cd06686303901d391069000f5a10d09694b68241e2) [email protected] declares a postinstall script `node./notify.js` that runs automatically on `npm install`. The script performs an HTTP GET to the hardcoded bare-IP endpoint http://91.201.215.48:8000/npm-poc-bcc with query parameters containing `os.hostname()` and the package name. The 9999.0.0 version, absence of any icon-library functionality expected from the package name, and callback-to-bare-IP shape match a dependency-confusion attack that identifies internal/private installers to the operator. Hostname is host-identifying data exfiltrated to an attacker-controlled destination without any installer opt-in.

    Affected packages

    Package

    Name: bcc-design-icons

    Purl: pkg:npm/bcc-design-icons

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    9999.0.0
    MAL-2026-14119 | CVE-DB