MAL-2026-2826

    Dashboard / Malicious Package / MAL-2026-2826

    MAL-2026-2826

    Published: 14 Apr 2026Last Modified: 23 Apr 2026

    Summary: Malicious code in dom-utils-lite (npm)

    Details: dom-utils-lite and centralogger, with identical payloads. On npm install, a postinstall hook fetches the attacker’s SSH public key from a Supabase storage bucket, appends it to ~/.ssh/authorized_keys, harvests the victim’s IP, username, and hostname, then uploads that metadata to the same Supabase project. A scheduler re-runs the chain every 60 seconds. Source: amazon-inspector (6c3c2db1ef8d166cd11088cbf7639ebcf90b2e7318580833f467dc7ce2b25588) The package dom-utils-lite was found to contain malicious code.

    Affected packages

    Package

    Name: dom-utils-lite

    Purl: pkg:npm/dom-utils-lite

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -None

    Affected versions

    MAL-2026-2826 | CVE-DB