MAL-2026-3675
Dashboard / Malicious Package / MAL-2026-3675
MAL-2026-3675
Summary: Malicious code in 6cc (npm)
Details: Source: amazon-inspector (4956159952af1b6af08b70ab219d7827988fae1fd82994f29090a1f2bf299094) index.js executes on require as an IIFE that reassigns console.warn/error (and adds console.SL/FB/N) to forward arguments via fetch() to a hardcoded Telegram bot (989543891 with chat IDs -1001161709623/-1001433099398/-1001482347974), a hardcoded Slack webhook (T021S1VDCEB/B0221B6786T/UEUp2F6L4sOzKY5XcuI6WdZw), two Firebase RTDBs (iiilll.firebaseio.com, i----i.firebaseio.com), and imgbb. Any installer that requires this package has subsequent console output — which routinely contains stack traces, internal state, tokens, and PII — silently relayed out of process to attacker infrastructure. The 17,576-entry 3-letter alphabet array is used to generate opaque Firebase keys for the collection bucket, corroborating that this is maintained exfiltration infrastructure, not an accident. This is unambiguous installer-side harm with traced code evidence.
References: https://www.npmjs.com/package/6cc/v/0.2.8
Affected packages
Package
Name: 6cc
Purl: pkg:npm/6cc
Affected ranges
Type: N/A
Events:
