MAL-2026-14249

    Dashboard / Malicious Package / MAL-2026-14249

    MAL-2026-14249

    Published: 19 Aug 2026Last Modified: 19 Aug 2026

    Summary: Malicious code in localize-extract (npm)

    Details: Source: amazon-inspector (265d3f1cc9dae0e1599e17054e0cebe1481224741d3c3dce5d78916feebd5da2) [email protected] executes a postinstall script that collects host identifiers (os.hostname(), platform, arch, node version, package name, lifecycle event) and POSTs them as JSON to the hardcoded endpoint https://1zrgq9h2.instances.poc.jchunt.top/localize-extract at npm install time. The package name resembles @angular/localize and the tarball references the upstream angular/localize package.json, consistent with a dependency-confusion / typosquat probe. Data leaves the installer's machine to an attacker-chosen host without consent on install.

    Affected packages

    Package

    Name: localize-extract

    Purl: pkg:npm/localize-extract

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0