MAL-2026-4401

    Dashboard / Malicious Package / MAL-2026-4401

    MAL-2026-4401

    Published: 21 May 2026Last Modified: 27 May 2026

    Summary: Malicious code in @kruzer/lib-ui (npm)

    Details: Source: amazon-inspector (c1bb1f66615de2b0b161721218d2bff4bb0e7100b5cb28b764fcc2e6f1ee671f) The published tarball's package.json contains a hardcoded npm registry auth token embedded in the `build:publish` script: `npm publish --tag alpha --//registry.npmjs.org/:_authToken=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`. The token is delivered to every installer of this package and grants publish privileges to the author's @kruzer/* npm scope. Anyone who installs or inspects this package can use the token to publish arbitrary (potentially malicious) versions of any package under @kruzer, which would then be pulled into all downstream installers of those packages. This is credential distribution to a third-party system (npm registry), not merely author self-harm — the blast radius extends to every downstream consumer of the @kruzer scope.

    Affected packages

    Package

    Name: @kruzer/lib-ui

    Purl: pkg:npm/%40kruzer%2Flib-ui

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.0.0-alpha.497
    0.0.0-alpha.491
    MAL-2026-4401 | CVE-DB