MAL-2026-15681

    Dashboard / Malicious Package / MAL-2026-15681

    MAL-2026-15681

    Published: 24 Aug 2026Last Modified: 4 Sept 2026

    Summary: Malicious code in @grab-food/order-sdk-web (npm)

    Details: Source: amazon-inspector (aa9b56bb1d69dc16b6095faea196af99809ad805b400a3c6b5499f896c8d74c2) Package published under a scope impersonating the Grab food-ordering brand with no real functionality (index.js exports an empty object). Its sole dependency, [email protected], is pinned to a tarball URL at https://registry.grivy-packages.com/ — a lookalike domain outside the npm registry. Installing @grab-food/[email protected] causes npm to fetch and install code from that attacker-controlled host into the installer's node_modules, bypassing npm registry inspection and running whatever lifecycle scripts and code the fetched tarball contains. This is a dependency-chain dropper: the visible package is a hollow lure, and the actual payload arrives via the non-registry dependency URL.

    Affected packages

    Package

    Name: @grab-food/order-sdk-web

    Purl: pkg:npm/%40grab-food/order-sdk-web

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    49.9.9
    MAL-2026-15681 | CVE-DB