MAL-2026-14239

    Dashboard / Malicious Package / MAL-2026-14239

    MAL-2026-14239

    Published: 19 Aug 2026Last Modified: 19 Aug 2026

    Summary: Malicious code in gaarf-node-bq (npm)

    Details: Source: amazon-inspector (1f61e7b586146a833e50d74ccdff68942b4514f66c38beca981d2ead87761633) gaarf-node-bq is a dependency-confusion / typosquat canary targeting the internal google/ads-api-report-fetcher (`gaarf`) package. The bin entry is an empty noop and the package ships no real functionality. Its postinstall lifecycle script collects host identifiers (os.hostname(), platform, arch, node version, package name, npm lifecycle event) and POSTs them as JSON to the hardcoded endpoint https://yu7pug2j.instances.poc.jchunt.top/gaarf-node-bq. Any installer that mis-resolves the private name to the public registry has its host metadata sent to that endpoint without consent at install time.

    Affected packages

    Package

    Name: gaarf-node-bq

    Purl: pkg:npm/gaarf-node-bq

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0
    MAL-2026-14239 | CVE-DB