MAL-2026-4477

    Dashboard / Malicious Package / MAL-2026-4477

    MAL-2026-4477

    Published: 22 May 2026Last Modified: 26 May 2026

    Summary: Malicious code in allbridge-example-react (npm)

    Details: Source: amazon-inspector (d1b559cd05fa1b995a6564d71a35fe6bd18897f030af24e064eed9a4ee63e787) package.json declares a preinstall lifecycle script that runs `wget` against https://webhook.site/64063d25-fcd3-44e5-a454-34845bc63250/ with query parameters carrying $(whoami), $(pwd), and $(hostname). The request fires unconditionally on every `npm install`, transmitting the installing user's username, working directory, and hostname to an attacker-controlled inspection endpoint with no opt-in or documented purpose. The package name impersonates the Allbridge project but ships no library code — only the manifest with the beacon and a single suspicious dependency. This is the canonical dependency-confusion reconnaissance pattern: a lure package that maps internal build environments to enable follow-on targeting.

    Affected packages

    Package

    Name: allbridge-example-react

    Purl: pkg:npm/allbridge-example-react

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    9.0.0
    MAL-2026-4477 | CVE-DB