MAL-2026-15565

    Dashboard / Malicious Package / MAL-2026-15565

    MAL-2026-15565

    Published: 29 Aug 2026Last Modified: 9 Sept 2026

    Summary: Malicious code in @testrelic/playwright-analytics (npm)

    Details: Source: amazon-inspector (c305bbe247587c98b06f039cdcf78066dbcd4fdacf5a5de0411023c2a4fcc97a) scripts/postinstall.cjs is registered as the package's postinstall lifecycle script and runs automatically on `npm install`. After a block of legitimate-looking config-scaffolding code, the file contains roughly 7 KB of whitespace padding followed by an obfuscated payload that reconstructs a large string via a custom Fisher–Yates shuffle, resolves the String `constructor` property (Function) to avoid any literal `Function`/`eval` token, and invokes `Function('', decodedBody)(decodedArg)`. Immediately before the invocation the script assigns `require`, `module`, `__dirname`, and `__filename` onto the global object so the decoded body can load arbitrary Node built-ins. The whitespace gap conceals the payload from casual review of the file, and the indirection through `String[constructor]` avoids the literal tokens static reviewers grep for. The bundled `dist/index.cjs`, `dist/reporter-entry.cjs`, and `dist/cli.cjs` additionally contain `require('child_process')` alongside outbound HTTP POST call sites and `ping` invocations. The package's declared identity (a Playwright analytics reporter under an unfamiliar `@testrelic` scope) is inconsistent with shipping an obfuscated postinstall dynamic-code loader.

    Affected packages

    Package

    Name: @testrelic/playwright-analytics

    Purl: pkg:npm/%40testrelic/playwright-analytics

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    2.13.0
    MAL-2026-15565 | CVE-DB