MAL-2026-4377

    Dashboard / Malicious Package / MAL-2026-4377

    MAL-2026-4377

    Published: 20 May 2026Last Modified: 27 May 2026

    Summary: Malicious code in @ctrl/plex (npm)

    Details: Source: amazon-inspector (20e1aad15739a79a359d88099a004fa395b66df8845c10823824e848f095c568) The @ctrl/* npm scope was compromised in the Shai-Hulud supply-chain incident (September 2025). Versions of @ctrl/plex published during and after the compromise window have been observed shipping credential-harvesting payloads that exfiltrate developer secrets (npm tokens, GitHub tokens, cloud credentials, SSH keys) and self-propagate by republishing other packages owned by the same maintainer. @ctrl/[email protected] falls within the affected version range for this scope. Installing this version is expected to execute attacker-controlled code that harvests installer credentials and attempts further package compromise.

    Affected packages

    Package

    Name: @ctrl/plex

    Purl: pkg:npm/%40ctrl%2Fplex

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    6.0.0
    MAL-2026-4377 | CVE-DB