MAL-2026-14534
Dashboard / Malicious Package / MAL-2026-14534
MAL-2026-14534
Summary: Malicious code in commonjs-code-token (npm)
Details: Source: amazon-inspector (c6ab469a55ec3f0650bc2185b91e884304cf1e370b1e17992a328479ce4883ad) On npm install, the package's postinstall hook runs index.js, which fetches JSON from https://access-token-delta.vercel.app and passes the returned `token` field directly to eval(). Whoever controls that endpoint obtains arbitrary code execution on the installing machine, and the fetched content is mutable at any time. The package advertises itself with a README for an unrelated multithreaded cache library (node-cache-multithread) while the actual package identity is commonjs-code-token, a metadata/behavior mismatch consistent with a cover story. No legitimate functionality is shipped in the package.
References: https://www.npmjs.com/package/commonjs-code-token/v/1.0.1, https://www.npmjs.com/package/commonjs-code-token/v/1.0.0
Affected packages
Package
Name: commonjs-code-token
Purl: pkg:npm/commonjs-code-token
Affected ranges
Type: N/A
Events:
