MAL-2026-14249
Dashboard / Malicious Package / MAL-2026-14249
MAL-2026-14249
Summary: Malicious code in localize-extract (npm)
Details: Source: amazon-inspector (265d3f1cc9dae0e1599e17054e0cebe1481224741d3c3dce5d78916feebd5da2) [email protected] executes a postinstall script that collects host identifiers (os.hostname(), platform, arch, node version, package name, lifecycle event) and POSTs them as JSON to the hardcoded endpoint https://1zrgq9h2.instances.poc.jchunt.top/localize-extract at npm install time. The package name resembles @angular/localize and the tarball references the upstream angular/localize package.json, consistent with a dependency-confusion / typosquat probe. Data leaves the installer's machine to an attacker-chosen host without consent on install.
Affected packages
Package
Name: localize-extract
Purl: pkg:npm/localize-extract
Affected ranges
Type: N/A
Events:
