MAL-2026-14534

    Dashboard / Malicious Package / MAL-2026-14534

    MAL-2026-14534

    Published: 26 Aug 2026Last Modified: 26 Aug 2026

    Summary: Malicious code in commonjs-code-token (npm)

    Details: Source: amazon-inspector (c6ab469a55ec3f0650bc2185b91e884304cf1e370b1e17992a328479ce4883ad) On npm install, the package's postinstall hook runs index.js, which fetches JSON from https://access-token-delta.vercel.app and passes the returned `token` field directly to eval(). Whoever controls that endpoint obtains arbitrary code execution on the installing machine, and the fetched content is mutable at any time. The package advertises itself with a README for an unrelated multithreaded cache library (node-cache-multithread) while the actual package identity is commonjs-code-token, a metadata/behavior mismatch consistent with a cover story. No legitimate functionality is shipped in the package.

    Affected packages

    Package

    Name: commonjs-code-token

    Purl: pkg:npm/commonjs-code-token

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.1
    1.0.0
    MAL-2026-14534 | CVE-DB