MAL-2026-4434

    Dashboard / Malicious Package / MAL-2026-4434

    MAL-2026-4434

    Published: 20 May 2026Last Modified: 27 May 2026

    Summary: Malicious code in @semacode/cli (npm)

    Details: Source: amazon-inspector (28a3662b8e26593b7bfec35d4d4f02595144885ee738891c4c9e6a89f9e50fbb) The bundled CLI (dist/index.js) contains a hardcoded outbound POST to https://sema.otimitare.online combined with reads of process.env and process.platform in the same module. The destination domain does not match any documented publisher infrastructure for a CLI tool and the call site issues an HTTP POST carrying environment- and platform-derived data. This pattern — hardcoded non-publisher C2 + env/platform reads + POST in a tool's main bundled entry — is the exfiltration shape and not consistent with normal telemetry from a reputable vendor (no opt-out, undocumented destination, suspicious lookalike-style hostname under a generic.online TLD).

    Affected packages

    Package

    Name: @semacode/cli

    Purl: pkg:npm/%40semacode%2Fcli

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.5.28
    MAL-2026-4434 | CVE-DB