MAL-2026-2825
Dashboard / Malicious Package / MAL-2026-2825
MAL-2026-2825
Published: 14 Apr 2026Last Modified: 23 Apr 2026
Summary: Malicious code in centralogger (npm)
Details: dom-utils-lite and centralogger, with identical payloads. On npm install, a postinstall hook fetches the attacker’s SSH public key from a Supabase storage bucket, appends it to ~/.ssh/authorized_keys, harvests the victim’s IP, username, and hostname, then uploads that metadata to the same Supabase project. A scheduler re-runs the chain every 60 seconds. Source: amazon-inspector (8fed5ef4339475826025c028e1e9ed8442753d98ebbdab903dd3a16880305062) The package centralogger was found to contain malicious code.
Affected packages
Package
Name: centralogger
Purl: pkg:npm/centralogger
Affected ranges
Type: SEMVER
Events:
Introduced- 0
Fixed -None
