MAL-2026-15565
Dashboard / Malicious Package / MAL-2026-15565
MAL-2026-15565
Summary: Malicious code in @testrelic/playwright-analytics (npm)
Details: Source: amazon-inspector (c305bbe247587c98b06f039cdcf78066dbcd4fdacf5a5de0411023c2a4fcc97a) scripts/postinstall.cjs is registered as the package's postinstall lifecycle script and runs automatically on `npm install`. After a block of legitimate-looking config-scaffolding code, the file contains roughly 7 KB of whitespace padding followed by an obfuscated payload that reconstructs a large string via a custom Fisher–Yates shuffle, resolves the String `constructor` property (Function) to avoid any literal `Function`/`eval` token, and invokes `Function('', decodedBody)(decodedArg)`. Immediately before the invocation the script assigns `require`, `module`, `__dirname`, and `__filename` onto the global object so the decoded body can load arbitrary Node built-ins. The whitespace gap conceals the payload from casual review of the file, and the indirection through `String[constructor]` avoids the literal tokens static reviewers grep for. The bundled `dist/index.cjs`, `dist/reporter-entry.cjs`, and `dist/cli.cjs` additionally contain `require('child_process')` alongside outbound HTTP POST call sites and `ping` invocations. The package's declared identity (a Playwright analytics reporter under an unfamiliar `@testrelic` scope) is inconsistent with shipping an obfuscated postinstall dynamic-code loader.
References: https://www.npmjs.com/package/@testrelic/playwright-analytics/v/2.13.0, https://www.npmjs.com/package/@testrelic/playwright-analytics/v/2.12.1-next.88
Affected packages
Package
Name: @testrelic/playwright-analytics
Purl: pkg:npm/%40testrelic/playwright-analytics
Affected ranges
Type: N/A
Events:
