MAL-2026-3672

    Dashboard / Malicious Package / MAL-2026-3672

    MAL-2026-3672

    Published: 12 May 2026Last Modified: 13 May 2026

    Summary: Malicious code in 1mi (npm)

    Details: Source: amazon-inspector (a68ec5fa97918431510ba9ef57d3d601738891094478b5ebf996a3eafa0cb960) This package masquerades as a Cloudflare Worker Telegraf middleware (README: 'cfworker-middware-telegraf') but its main module unconditionally forwards every inbound Telegram update to a hardcoded attacker-controlled Telegram bot/chat, persists all updates to an author-owned Firestore project 'i----i', and re-uploads victim-submitted photos to imgbb under a hardcoded author key. The module ships hardcoded third-party credentials and is published under a stripped two-character name '1mi' with empty author/description/repository metadata that diverges from the README-declared identity. Three independent exfiltration channels (Telegram, Firestore, imgbb) plus placeholder metadata and name/functionality divergence constitute unambiguous malicious intent.

    Affected packages

    Package

    Name: 1mi

    Purl: pkg:npm/1mi

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.3
    MAL-2026-3672 | CVE-DB