MAL-2026-15589
Dashboard / Malicious Package / MAL-2026-15589
MAL-2026-15589
Summary: Malicious code in autobahn-electron-probe (npm)
Details: Source: amazon-inspector (b9a749e23bbf7c5ca871c797923855dc2c7fe1006c5843ed8a13292d7fbd4256) package.json declares preinstall and postinstall lifecycle scripts that run curl against http://da9ohqqvbsgu1166tuu0rrroxsztr18dt.cyowl.com/autobahn-electron-probe/, sending the installer's username (whoami), hostname, current working directory, and a timestamp as query parameters over plain HTTP. The long unique subdomain under cyowl.com is a DNS-callback / OAST-style exfiltration pattern. The scripts fire automatically on npm install without any user action, and the package ships no functional module code — the lifecycle beacon is the entire payload. The package name resembles the Autobahn WebSocket project and Electron, but the shipped contents perform only host reconnaissance and beaconing. Source: ossf-package-analysis (d3c07ff64c9729469df8453fb5fd6fa15e1099e81916496d741fe10297e44fc7) The OpenSSF Package Analysis project identified 'autobahn-electron-probe' @ 99.99.1 (npm) as malicious. It is considered malicious because: - The package executes one or more commands associated with malicious behavior.
References: https://www.npmjs.com/package/autobahn-electron-probe/v/99.99.1, https://www.npmjs.com/package/autobahn-electron-probe/v/99.99.2, https://www.npmjs.com/package/autobahn-electron-probe/v/99.99.3
Affected packages
Package
Name: autobahn-electron-probe
Purl: pkg:npm/autobahn-electron-probe
Affected ranges
Type: N/A
Events:
