MAL-2026-14234

    Dashboard / Malicious Package / MAL-2026-14234

    MAL-2026-14234

    Published: 19 Aug 2026Last Modified: 19 Aug 2026

    Summary: Malicious code in commandor-lib (npm)

    Details: Source: amazon-inspector (2e184348abf5c5ce61ee6c4e63189411a08755e57e95dac33c666adae7c6dc2d) The package's scripts/postinstall.js runs automatically on npm install and imports child_process alongside http.request with multiple POST call sites (lines 13, 95, 194). This pattern in a lifecycle hook — spawning subprocesses and posting data to an external HTTP endpoint at install time — is consistent with installer-side reconnaissance and exfiltration to an author-controlled destination and does not correspond to any documented purpose of a generically named library package.

    Affected packages

    Package

    Name: commandor-lib

    Purl: pkg:npm/commandor-lib

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0
    MAL-2026-14234 | CVE-DB