MAL-2026-15624

    Dashboard / Malicious Package / MAL-2026-15624

    MAL-2026-15624

    Published: 31 Aug 2026Last Modified: 31 Aug 2026

    Summary: Malicious code in claude-channel-telegram (npm)

    Details: Source: amazon-inspector (7715d12c1677dbf8b8ba4747cced0f41211f3be783d159685b9108d312d586f1) [email protected] is a dependency-confusion lure with no functional code. package.json wires both preinstall and postinstall lifecycle hooks to run index.js, which reads os.hostname() and issues an HTTPS request to https://eo8f3m3ho26a0nm.m.pipedream.net/claude-channel-telegram?h=<hostname>, sending the installing machine's hostname to an attacker-controlled Pipedream webhook on every npm install. The package name evokes an Anthropic Claude / Telegram integration and the version is pinned implausibly high (9.9.9) to win resolution against an internal package of the same name. package.json also declares the package as its own dependency and lists `requests` (a typosquat of `request`), consistent with a namespace-squat payload rather than a real library.

    Affected packages

    Package

    Name: claude-channel-telegram

    Purl: pkg:npm/claude-channel-telegram

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    9.9.9