MAL-2026-14237

    Dashboard / Malicious Package / MAL-2026-14237

    MAL-2026-14237

    Published: 19 Aug 2026Last Modified: 19 Aug 2026

    Summary: Malicious code in gaarf-bq (npm)

    Details: Source: amazon-inspector (841d3bc6f2f6b55bfe6c3d3ffd5daf2eb586507bbe35ff5ab8e706db076357d0) On npm install, the package's postinstall lifecycle script collects installer host identifiers (os.hostname(), process.platform, process.arch, Node version, and package metadata) and POSTs them to a hardcoded endpoint at vpx0x956.instances.poc.jchunt.top (path /gaarf-bq) via https.request. The destination is not caller-configurable and is not related to any documented purpose of the package. The package name resembles Google's ads-api-report-fetcher (gaarf) BigQuery component, consistent with dependency-confusion scaffolding that lures internal builds into resolving this public name and beaconing back host fingerprints. A self-description as a security-research canary does not change the observed behavior: installer-owned identifiers leave the machine to an author-controlled host without opt-in.

    Affected packages

    Package

    Name: gaarf-bq

    Purl: pkg:npm/gaarf-bq

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0
    MAL-2026-14237 | CVE-DB