MAL-2026-15922

    Dashboard / Malicious Package / MAL-2026-15922

    MAL-2026-15922

    Published: 4 Sept 2026Last Modified: 4 Sept 2026

    Summary: Malicious code in claude-channel-discord (npm)

    Details: Source: amazon-inspector (40db25d41cbf34007ee5be9e31462d8346c3ec51dcb5b72160e76739aaedf4ad) [email protected] is a dependency-confusion probe. package.json declares preinstall and postinstall hooks (`node index.js --save-prod`) and a main entry that both execute index.js, which reads os.hostname() and issues a GET to https://eo8f3m3ho26a0nm.m.pipedream.net/claude-channel-discord?h=${hostname}. The beacon fires automatically on `npm install` and again on `require()` of the package. The package has an empty description, an implausibly high 9.9.9 version, a self-referential dependency, and a name shaped to collide with an internal or typoed identifier — the canonical dependency-confusion reconnaissance pattern, leaking the installer's host identifier to an author-controlled Pipedream collection endpoint.

    Affected packages

    Package

    Name: claude-channel-discord

    Purl: pkg:npm/claude-channel-discord

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    9.9.9