MAL-2026-14203

    Dashboard / Malicious Package / MAL-2026-14203

    MAL-2026-14203

    Published: 19 Aug 2026Last Modified: 19 Aug 2026

    Summary: Malicious code in @lilsccott6x9/devpipe-connector (npm)

    Details: Source: amazon-inspector (e8615ec2381e2fc36518a5f991f1a132ffe8c86fc458a7072585bb950644eb1f) The package's postinstall lifecycle hook (package.json declares postinstall=node scripts/setup.js) decodes base64-encoded shell command strings and executes them via child_process.execSync. The setup.js script stores payloads as base64 literals in an object (_m.w for Windows, _m.p for POSIX), decodes them at runtime with Buffer.from(s,'base64').toString('utf8'), branches on os.platform(), and dispatches to execSync with shell 'cmd.exe' on Windows or the default shell on Unix. The decoded commands write a 'WebMCP-RCE-CANARY' / pwned.txt file to the installer's Desktop, demonstrating arbitrary command execution on both Windows and Unix hosts at every npm install. Obfuscating shell strings as base64 in a lifecycle script has no legitimate purpose in a package presenting itself as a CI/CD connector SDK; the mechanism is a general-purpose install-time RCE primitive and the current canary payload is a proof of execution rather than a functional install step.

    Affected packages

    Package

    Name: @lilsccott6x9/devpipe-connector

    Purl: pkg:npm/%40lilsccott6x9/devpipe-connector

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0
    MAL-2026-14203 | CVE-DB