MAL-2026-4364
Dashboard / Malicious Package / MAL-2026-4364
MAL-2026-4364
Summary: Malicious code in @aswinsparky/api (npm)
Details: Source: amazon-inspector (8cceefd98563e2885501c896472471f2bb20b77103ad99c253775570cae6b4fe) index.js line 11 issues a fetch() to the hardcoded URL https://api.aswinsparky.qzz.io carrying values read from process.env. The destination is a freshly-registered qzz.io subdomain matching the author's npm scope (@aswinsparky), not a documented vendor or publisher infrastructure. There is no configuration option, no user-supplied URL, and no documented purpose that would explain shipping environment-variable contents to this host. Any consumer that imports or invokes this package leaks process environment values — typically containing API keys, tokens, and secrets — to the author-controlled endpoint.
Affected packages
Package
Name: @aswinsparky/api
Purl: pkg:npm/%40aswinsparky%2Fapi
Affected ranges
Type: N/A
Events:
