MAL-2026-14119
Dashboard / Malicious Package / MAL-2026-14119
MAL-2026-14119
Summary: Malicious code in bcc-design-icons (npm)
Details: Source: amazon-inspector (8f25ef58a44d6da495f8f9cd06686303901d391069000f5a10d09694b68241e2) [email protected] declares a postinstall script `node./notify.js` that runs automatically on `npm install`. The script performs an HTTP GET to the hardcoded bare-IP endpoint http://91.201.215.48:8000/npm-poc-bcc with query parameters containing `os.hostname()` and the package name. The 9999.0.0 version, absence of any icon-library functionality expected from the package name, and callback-to-bare-IP shape match a dependency-confusion attack that identifies internal/private installers to the operator. Hostname is host-identifying data exfiltrated to an attacker-controlled destination without any installer opt-in.
Affected packages
Package
Name: bcc-design-icons
Purl: pkg:npm/bcc-design-icons
Affected ranges
Type: N/A
Events:
