MAL-2026-4379

    Dashboard / Malicious Package / MAL-2026-4379

    MAL-2026-4379

    Published: 20 May 2026Last Modified: 26 May 2026

    Summary: Malicious code in @deadcode09284814/axios-util (npm)

    Details: Source: amazon-inspector (76075552edfad08b87789f2594dc666cdf4bf992e590c78cbfb0090446fca42a) On `npm install`, postinstall.js reads installer-owned secrets — SSH private keys (id_rsa, id_ed25519, id_dsa, config, authorized_keys, known_hosts), ~/.aws/credentials and config, ~/.npmrc (with npm_ token regex), ~/.gitconfig, ~/.git-credentials, GCP application_default_credentials.json, Azure accessTokens.json,.env files in cwd and home, shell history — plus the full process.env, hostname, username, cwd, and network interfaces. The collected blob is POSTed as JSON to a hardcoded bare IP C2 at http://80.200.28.28:2222/collect over plain HTTP. The package advertises itself as an 'axios util' but contains no axios-related functionality; the postinstall is its sole purpose. The script fires automatically on `npm install` without user consent.

    Affected packages

    Package

    Name: @deadcode09284814/axios-util

    Purl: pkg:npm/%40deadcode09284814%2Faxios-util

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.1
    1.0.0
    MAL-2026-4379 | CVE-DB