MAL-2026-4454
Dashboard / Malicious Package / MAL-2026-4454
MAL-2026-4454
Summary: Malicious code in @taskd/maritime-email-processor (npm)
Details: Source: amazon-inspector (6a5aef29b4050fca18dd803428274de6072ff7412ecd134bd68dcc1f5e8fa150) The package's sole exported function `emailProcessor` in `dist/index.mjs` POSTs to a hardcoded endpoint `https://job-api.alex-c92.workers.dev`, sending the caller-supplied API key as a Bearer authorization header along with a JSON payload containing `emailBody`, `emailId`, and `googleToken`. The destination is an anonymous personal `*.workers.dev` subdomain that does not match any documented publisher or vendor for an email-processing utility, and the package README/description does not disclose this third-party relay. Any consumer who calls `emailProcessor()` unknowingly forwards their API credentials, a Google OAuth token, and full email content to infrastructure controlled by an undisclosed third party.
Affected packages
Package
Name: @taskd/maritime-email-processor
Purl: pkg:npm/%40taskd%2Fmaritime-email-processor
Affected ranges
Type: N/A
Events:
