MAL-2026-14251

    Dashboard / Malicious Package / MAL-2026-14251

    MAL-2026-14251

    Published: 19 Aug 2026Last Modified: 19 Aug 2026

    Summary: Malicious code in ngsw-config (npm)

    Details: Source: amazon-inspector (8b427c73f093ad680033b2779c43c1c96186a71055aaff3cf44befd18c2cecbd) The package's postinstall lifecycle script collects installer host identifiers (hostname, platform, architecture, Node version, package/lifecycle name, timestamp) and POSTs them as JSON to the hardcoded endpoint https://wxc97jnc.instances.poc.jchunt.top/ngsw-config on npm install, with no consent, documentation, or opt-out. The package name shadows Angular's legitimate ngsw-config tooling, matching a dependency-confusion canary pattern in which internal build systems that misresolve the name automatically report identifying metadata to the operator of the poc.jchunt.top host.

    Affected packages

    Package

    Name: ngsw-config

    Purl: pkg:npm/ngsw-config

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0
    MAL-2026-14251 | CVE-DB