MAL-2026-4565

    Dashboard / Malicious Package / MAL-2026-4565

    MAL-2026-4565

    Published: 21 May 2026Last Modified: 26 May 2026

    Summary: Malicious code in fnd-stores (npm)

    Details: Source: amazon-inspector (62c9035e303ec731c71c689ed77eed17b245cd4adc475cb616ff94991539aa56) On `npm install`, the package's postinstall hook runs `node index.js`, which collects the installer's hostname, OS platform, current working directory, CI environment indicators, Node version, and OS username via `os.hostname()`, `os.platform()`, `os.userInfo()`, `process.cwd()`, and process env, and POSTs the payload as JSON to `https://webhook.site/604bab71-0179-419e-998e-6f15e524bfd7` (a publisher-controlled webhook bin). The README self-describes the package as a dependency-confusion canary targeting an internal package namespace, and the name is chosen to collide with that internal scope. Any developer or build pipeline that resolves this package leaks internal hostnames, usernames, working-directory paths, and CI job metadata to a third party at install time, without consent. Claimed 'authorized research' status does not change the installer-side harm.

    Affected packages

    Package

    Name: fnd-stores

    Purl: pkg:npm/fnd-stores

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.0.7
    0.0.6