MAL-2026-14232

    Dashboard / Malicious Package / MAL-2026-14232

    MAL-2026-14232

    Published: 19 Aug 2026Last Modified: 19 Aug 2026

    Summary: Malicious code in chromeos-webdriver-cli (npm)

    Details: Source: amazon-inspector (1bbf3413f6465a1f8bb628dcdb79f59ac7c197bbfba2024202c9915f95ad8161) The package's postinstall script runs on `npm install` and issues an HTTPS POST to https://kvpq6u62.instances.poc.jchunt.top/chromeos-webdriver-cli carrying installer-identifying fields (os.hostname(), platform, arch, node version, package name, timestamp). The destination is a hardcoded non-first-party host reached without user consent or configuration. The subdomain shape (random-token under instances.poc.jchunt.top) is consistent with a dependency-confusion / typo-squat canary beacon that discloses internal hostnames and environment metadata to a third party at install time.

    Affected packages

    Package

    Name: chromeos-webdriver-cli

    Purl: pkg:npm/chromeos-webdriver-cli

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0