MAL-2026-14591

    Dashboard / Malicious Package / MAL-2026-14591

    MAL-2026-14591

    Published: 28 Aug 2026Last Modified: 28 Aug 2026

    Summary: Malicious code in cacao1 (npm)

    Details: Source: amazon-inspector (403a43aab3b982d17c5c01d7df45149d796e7185f4137bf4a92675351a1b50e8) The package has no advertised functionality (empty description, self-referential dependency on its own name at ^9.9.9). Its package.json declares both preinstall and postinstall lifecycle scripts that execute index.js, which reads os.hostname() and issues an HTTP GET to https://eo8f3m3ho26a0nm.m.pipedream.net/cacao1 with the hostname included as a query parameter. Installing the package therefore causes the installer's hostname to be transmitted to a hardcoded third-party collector controlled by the package author. The structure (empty description, self-dependency, lifecycle-triggered beacon to a pipedream.net collector, unusual 9.9.9 version) matches a dependency-confusion beacon rather than a functional library. Source: ossf-package-analysis (7e80e85bc2ce7bba9bc4f288f4757cb9921d0fc4d7635c0a07ba35d19382df79) The OpenSSF Package Analysis project identified 'cacao1' @ 9.9.9 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity.

    Affected packages

    Package

    Name: cacao1

    Purl: pkg:npm/cacao1

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    9.9.9
    MAL-2026-14591 | CVE-DB