MAL-2026-4377
Dashboard / Malicious Package / MAL-2026-4377
MAL-2026-4377
Summary: Malicious code in @ctrl/plex (npm)
Details: Source: amazon-inspector (20e1aad15739a79a359d88099a004fa395b66df8845c10823824e848f095c568) The @ctrl/* npm scope was compromised in the Shai-Hulud supply-chain incident (September 2025). Versions of @ctrl/plex published during and after the compromise window have been observed shipping credential-harvesting payloads that exfiltrate developer secrets (npm tokens, GitHub tokens, cloud credentials, SSH keys) and self-propagate by republishing other packages owned by the same maintainer. @ctrl/[email protected] falls within the affected version range for this scope. Installing this version is expected to execute attacker-controlled code that harvests installer credentials and attempts further package compromise.
References: https://www.npmjs.com/package/@ctrl/plex/v/6.0.0
Affected packages
Package
Name: @ctrl/plex
Purl: pkg:npm/%40ctrl%2Fplex
Affected ranges
Type: N/A
Events:
