MAL-2026-4391

    Dashboard / Malicious Package / MAL-2026-4391

    MAL-2026-4391

    Published: 21 May 2026Last Modified: 26 May 2026

    Summary: Malicious code in @gad360/apothem (npm)

    Details: Source: amazon-inspector (4f5e509ba6aa2f781391f03ff37ea8005440c1d1106391bdfa91abae06336ad3) The package's package.json declares a postinstall hook ("postinstall": "node install.js") that runs install.js automatically on npm install. install.js requires fs, os, https, and child_process, reads environment variables and host metadata (process.env, process.platform, process.arch, os.tmpdir, fs.readFileSync), and issues an https.get to the hardcoded endpoint https://ahmedgad.com. The combination of a hardcoded non-publisher destination with environment/system reads inside a lifecycle script is the canonical install-time exfiltration shape. The destination is unrelated to any documented vendor SDK or runtime CDN, and there is no version pinning, hash verification, or build-from-source justification for the network call.

    Affected packages

    Package

    Name: @gad360/apothem

    Purl: pkg:npm/%40gad360%2Fapothem

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.1.0
    MAL-2026-4391 | CVE-DB