MAL-2026-15590

    Dashboard / Malicious Package / MAL-2026-15590

    MAL-2026-15590

    Published: 30 Aug 2026Last Modified: 31 Aug 2026

    Summary: Malicious code in com.db.autobahn.notification-center-electron (npm)

    Details: Source: amazon-inspector (4ae376efc666d8e07f356f9f3cbafe2dfc99e221a150ff96548db4a2b91bb452) package.json declares preinstall and postinstall lifecycle scripts that automatically run curl on `npm install` to send installer identity (`whoami`, `hostname`, `$PWD`, timestamp) as query-string parameters to a long-random-label third-party host (`da9nfhavbsgte1dqq8fgrbb7fyfekc37i.cyowl.com`) over plain HTTP. The package name (`com.db.autobahn.notification-center-electron`) and implausibly high version (88.88.1) are consistent with a dependency-confusion lure targeting an internal scope; installing this package leaks host reconnaissance data to an external endpoint. Source: ossf-package-analysis (fe0ae07b99c275a092bcb2e4836aeb711a02f98def45f54f91bcf5ba38873807) The OpenSSF Package Analysis project identified 'com.db.autobahn.notification-center-electron' @ 88.88.2 (npm) as malicious. It is considered malicious because: - The package executes one or more commands associated with malicious behavior.

    Affected packages

    Package

    Name: com.db.autobahn.notification-center-electron

    Purl: pkg:npm/com.db.autobahn.notification-center-electron

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    88.88.2
    88.88.1