MAL-2026-16111

    Dashboard / Malicious Package / MAL-2026-16111

    MAL-2026-16111

    Published: 10 Sept 2026Last Modified: 10 Sept 2026

    Summary: Malicious code in etoro-aggregator (npm)

    Details: Source: amazon-inspector (6e7805793fe0fa0f03f018a31574ec577e87f249231d9ada54cdf052395a65d1) [email protected] ships a preinstall.js that runs automatically on npm install and issues an HTTP GET to http://209.126.81.147/etoro-depconf-poce346552f776f/npm/<hostname>/<username>/<cwd>, encoding os.hostname(), os.userInfo().username, and process.cwd() as URL path segments. The version number (999.0.0), generic package name, and absence of any legitimate library code are consistent with a dependency-confusion lure: installing the package causes the installer's host identity to be sent to an attacker-controlled bare-IP endpoint over plaintext HTTP, providing reconnaissance for targeted follow-on attacks against organizations whose internal package names collide with this name.

    Affected packages

    Package

    Name: etoro-aggregator

    Purl: pkg:npm/etoro-aggregator

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    999.0.0