MAL-2026-16120

    Dashboard / Malicious Package / MAL-2026-16120

    MAL-2026-16120

    Published: 10 Sept 2026Last Modified: 10 Sept 2026

    Summary: Malicious code in etoro-core (npm)

    Details: Source: amazon-inspector (64a03f7bbaa2cb54ffea9a0c98d22bdc2fdb0d368846beefbd8d9c3b5ab3f644) The package's preinstall lifecycle script (preinstall.js) issues an HTTP GET to the hardcoded bare-IP endpoint http://209.126.81.147/etoro-depconf-poce346552f776f/npm/ with os.hostname(), os.userInfo().username, and process.cwd() embedded in the URL path. This runs automatically on `npm install` and transmits installer host identity over plaintext HTTP to an attacker-controlled destination. The package name and inflated 999.0.0 version are consistent with a dependency-confusion payload targeting an internal `etoro-core` name.

    Affected packages

    Package

    Name: etoro-core

    Purl: pkg:npm/etoro-core

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    999.0.0