MAL-2026-15590
Dashboard / Malicious Package / MAL-2026-15590
MAL-2026-15590
Summary: Malicious code in com.db.autobahn.notification-center-electron (npm)
Details: Source: amazon-inspector (4ae376efc666d8e07f356f9f3cbafe2dfc99e221a150ff96548db4a2b91bb452) package.json declares preinstall and postinstall lifecycle scripts that automatically run curl on `npm install` to send installer identity (`whoami`, `hostname`, `$PWD`, timestamp) as query-string parameters to a long-random-label third-party host (`da9nfhavbsgte1dqq8fgrbb7fyfekc37i.cyowl.com`) over plain HTTP. The package name (`com.db.autobahn.notification-center-electron`) and implausibly high version (88.88.1) are consistent with a dependency-confusion lure targeting an internal scope; installing this package leaks host reconnaissance data to an external endpoint. Source: ossf-package-analysis (fe0ae07b99c275a092bcb2e4836aeb711a02f98def45f54f91bcf5ba38873807) The OpenSSF Package Analysis project identified 'com.db.autobahn.notification-center-electron' @ 88.88.2 (npm) as malicious. It is considered malicious because: - The package executes one or more commands associated with malicious behavior.
References: https://www.npmjs.com/package/com.db.autobahn.notification-center-electron/v/88.88.2, https://www.npmjs.com/package/com.db.autobahn.notification-center-electron/v/88.88.1
Affected packages
Package
Name: com.db.autobahn.notification-center-electron
Purl: pkg:npm/com.db.autobahn.notification-center-electron
Affected ranges
Type: N/A
Events:
