MAL-2026-3717
Dashboard / Malicious Package / MAL-2026-3717
MAL-2026-3717
Summary: Malicious code in truffle-js (npm)
Details: Source: amazon-inspector (52bd5b41de871fbbc8c5895f63dfec08ba2ff6ecb9ea03fa6fdb5d9245c74616) The package.json lifecycle script invokes require('child_process').execSync with a curl command at install time. Running curl through child_process during an npm install lifecycle hook causes any installer to execute remote content fetched over the network, without consent, as soon as `npm install` runs. The package name also resembles the widely-used 'truffle' Ethereum development toolkit, consistent with a typosquat lure. There is no legitimate reason for a small utility package to shell out to curl from its package.json install hook. Source: ossf-package-analysis (c190460255cf713f1797bacece635079c6d3db6a45a58199af29ab1acc9faa2f) The OpenSSF Package Analysis project identified 'truffle-js' @ 2.0.0 (npm) as malicious. It is considered malicious because: - The package executes one or more commands associated with malicious behavior.
References: https://www.npmjs.com/package/truffle-js/v/1.0.0
Affected packages
Package
Name: truffle-js
Purl: pkg:npm/truffle-js
Affected ranges
Type: N/A
Events:
