MAL-2026-14235
Dashboard / Malicious Package / MAL-2026-14235
MAL-2026-14235
Summary: Malicious code in config-helper-kit (npm)
Details: Source: amazon-inspector (1033a9895c7d1a1b4d2c3f671caa239bd40f3985ab71d096fd25fbb7c977ef71) [email protected] exposes a default function getPlugin that issues an HTTPS request to a hardcoded bare-IP host (https://31.97.137.157:45000/icons/109) and passes the returned data.credits field into `new Function('require','module',...)`, executing attacker-controlled JavaScript in the caller's Node.js process with `require` and `module` injected. The file also ships an unused helper referencing legitimate CDN hostnames (cloudflare, fastly, akamai, cdnjs) and uses icon/logo/credits naming, while the actual network target is a bare IP unrelated to any CDN. The package's README advertises it as a TypeScript/Tailwind config helper; the remote-code-fetch-and-execute behavior is undocumented and unrelated to that purpose. Any consumer that imports and invokes the default export grants the operator of 31.97.137.157:45000 arbitrary code execution on the installer's host.
Affected packages
Package
Name: config-helper-kit
Purl: pkg:npm/config-helper-kit
Affected ranges
Type: N/A
Events:
