MAL-2026-14192

    Dashboard / Malicious Package / MAL-2026-14192

    MAL-2026-14192

    Published: 19 Aug 2026Last Modified: 19 Aug 2026

    Summary: Malicious code in tfjs-inference (npm)

    Details: Source: amazon-inspector (52ebb387c7f1f9bb3e96df6f8006cabc9141ddd1da35a58bfc14b42f2f6864eb) The package name typosquats TensorFlow.js and its npm postinstall lifecycle script collects installer host identifiers (hostname, platform, arch, Node.js version, package name) and POSTs them as JSON to the hardcoded third-party host zl2u2d1x.instances.poc.jchunt.top at path /tfjs-inference. The exfiltration fires automatically on `npm install` with no opt-in and no configuration. Internal comments self-label the package as a security research canary, but the destination is author-controlled and the installer receives no notice or consent prompt.

    Affected packages

    Package

    Name: tfjs-inference

    Purl: pkg:npm/tfjs-inference

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0
    MAL-2026-14192 | CVE-DB