MAL-2026-16118
Dashboard / Malicious Package / MAL-2026-16118
MAL-2026-16118
Summary: Malicious code in etoro-charts (npm)
Details: Source: amazon-inspector (484ce8002025d68c4a60feca03aec63425a66b85e2465415a4fc5a29e3a61f43) The package's preinstall.js runs automatically on npm install and issues an HTTP GET to a hardcoded bare IP (http://209.126.81.147/etoro-depconf-poce346552f776f/npm/<hostname>/<username>/<cwd>), embedding the installer's OS hostname (os.hostname()), OS username (os.userInfo().username), and current working directory (process.cwd()) as URL path segments. The package uses a generic 'eToro' brand name with a version pinned at 999.0.0, a pattern consistent with dependency-confusion attacks that aim to win resolution against an internal package of the same name. Installing the package causes installer-side identifiers to be sent in cleartext to an attacker-controlled endpoint.
Affected packages
Package
Name: etoro-charts
Purl: pkg:npm/etoro-charts
Affected ranges
Type: N/A
Events:
