MAL-2026-4364

    Dashboard / Malicious Package / MAL-2026-4364

    MAL-2026-4364

    Published: 20 May 2026Last Modified: 27 May 2026

    Summary: Malicious code in @aswinsparky/api (npm)

    Details: Source: amazon-inspector (8cceefd98563e2885501c896472471f2bb20b77103ad99c253775570cae6b4fe) index.js line 11 issues a fetch() to the hardcoded URL https://api.aswinsparky.qzz.io carrying values read from process.env. The destination is a freshly-registered qzz.io subdomain matching the author's npm scope (@aswinsparky), not a documented vendor or publisher infrastructure. There is no configuration option, no user-supplied URL, and no documented purpose that would explain shipping environment-variable contents to this host. Any consumer that imports or invokes this package leaks process environment values — typically containing API keys, tokens, and secrets — to the author-controlled endpoint.

    Affected packages

    Package

    Name: @aswinsparky/api

    Purl: pkg:npm/%40aswinsparky%2Fapi

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.1