MAL-2026-16112

    Dashboard / Malicious Package / MAL-2026-16112

    MAL-2026-16112

    Published: 10 Sept 2026Last Modified: 10 Sept 2026

    Summary: Malicious code in etoro-analytics (npm)

    Details: Source: amazon-inspector (a87dfbd5f51b30470e8d1df702e746f7c8141fdaafab2237fd1f2ef4897d9ae5) The package's preinstall lifecycle script runs automatically on `npm install` and sends the installer's hostname, OS username, and current working directory to a hardcoded remote host at http://209.126.81.147 over plain HTTP, embedding the values as URL path segments under `/etoro-depconf-poce346552f776f/npm/`. The destination is a bare IP address, not configurable, and unrelated to any legitimate publisher infrastructure. The `999.0.0` version and eToro-themed name are consistent with a dependency-confusion lure targeting an internal package name.

    Affected packages

    Package

    Name: etoro-analytics

    Purl: pkg:npm/etoro-analytics

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    999.0.0