MAL-2026-4401
Dashboard / Malicious Package / MAL-2026-4401
MAL-2026-4401
Summary: Malicious code in @kruzer/lib-ui (npm)
Details: Source: amazon-inspector (c1bb1f66615de2b0b161721218d2bff4bb0e7100b5cb28b764fcc2e6f1ee671f) The published tarball's package.json contains a hardcoded npm registry auth token embedded in the `build:publish` script: `npm publish --tag alpha --//registry.npmjs.org/:_authToken=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`. The token is delivered to every installer of this package and grants publish privileges to the author's @kruzer/* npm scope. Anyone who installs or inspects this package can use the token to publish arbitrary (potentially malicious) versions of any package under @kruzer, which would then be pulled into all downstream installers of those packages. This is credential distribution to a third-party system (npm registry), not merely author self-harm — the blast radius extends to every downstream consumer of the @kruzer scope.
References: https://www.npmjs.com/package/@kruzer/lib-ui/v/0.0.0-alpha.497, https://www.npmjs.com/package/@kruzer/lib-ui/v/0.0.0-alpha.491
Affected packages
Package
Name: @kruzer/lib-ui
Purl: pkg:npm/%40kruzer%2Flib-ui
Affected ranges
Type: N/A
Events:
