MAL-2026-15923

    Dashboard / Malicious Package / MAL-2026-15923

    MAL-2026-15923

    Published: 4 Sept 2026Last Modified: 4 Sept 2026

    Summary: Malicious code in line-through (npm)

    Details: Source: amazon-inspector (f080fb3d5e59c5c950dd4dd0c2eb1841cdc2943e1543bd7803f7ca27d1756e60) The package's package.json preinstall hook runs vishu.js, which at npm install time collects the installer's public IP (via api.ipify.org), OS hostname, and GitHub Actions / CI environment variables (CI, GITHUB_ACTIONS, GITHUB_WORKFLOW, GITHUB_RUN_ID, and related identifiers), then sends them as query parameters in an HTTPS GET to a hardcoded collector at https://webhook.site/66059630-2030-4b44-b2df-d37e02be0a7d. It also performs a DNS lookup encoding the hostname as a subdomain of an out-of-band collaborator domain (left as the placeholder your-collab-domain.oastify.com). Behavior fires automatically on npm install with no user interaction.

    Affected packages

    Package

    Name: line-through

    Purl: pkg:npm/line-through

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0