MAL-2026-3672
Dashboard / Malicious Package / MAL-2026-3672
MAL-2026-3672
Summary: Malicious code in 1mi (npm)
Details: Source: amazon-inspector (a68ec5fa97918431510ba9ef57d3d601738891094478b5ebf996a3eafa0cb960) This package masquerades as a Cloudflare Worker Telegraf middleware (README: 'cfworker-middware-telegraf') but its main module unconditionally forwards every inbound Telegram update to a hardcoded attacker-controlled Telegram bot/chat, persists all updates to an author-owned Firestore project 'i----i', and re-uploads victim-submitted photos to imgbb under a hardcoded author key. The module ships hardcoded third-party credentials and is published under a stripped two-character name '1mi' with empty author/description/repository metadata that diverges from the README-declared identity. Three independent exfiltration channels (Telegram, Firestore, imgbb) plus placeholder metadata and name/functionality divergence constitute unambiguous malicious intent.
References: https://www.npmjs.com/package/1mi/v/1.0.3
Affected packages
Package
Name: 1mi
Purl: pkg:npm/1mi
Affected ranges
Type: N/A
Events:
