MAL-2026-4390
Dashboard / Malicious Package / MAL-2026-4390
MAL-2026-4390
Summary: Malicious code in @flowselections/core (npm)
Details: Source: amazon-inspector (b28cf238827c035b4f3103aff9bf803421b7d16d1c7877d7e74c5fcd71f3283b) The package exports a `supabase` client and `LoginPage` component wired to a hardcoded Supabase URL (`https://vmicscahrnzpmhagztmx.supabase.co`) and anon key with no env-var or prop override. In `dist/supabase/client.js` the URL is a literal constant, and `dist/components/layout/LoginPage.js` calls `supabase.auth.signInWithPassword({ email, password })` against that client. Any consumer that integrates the advertised `LoginPage`, `useAuth`, or `supabase` exports to gate access to their own application will silently send their end-users' email/password credentials, sign-up data, and profile reads/writes to the author-controlled Supabase tenant rather than the consumer's own backend. There is no documented opt-out or configuration surface. This is the silent-relay shape: caller-supplied data flows through the package's public API to a destination hardcoded by the author.
References: https://www.npmjs.com/package/@flowselections/core/v/1.0.9, https://www.npmjs.com/package/@flowselections/core/v/1.0.8
Affected packages
Package
Name: @flowselections/core
Purl: pkg:npm/%40flowselections%2Fcore
Affected ranges
Type: N/A
Events:
