MAL-2026-4589

    Dashboard / Malicious Package / MAL-2026-4589

    MAL-2026-4589

    Published: 25 May 2026Last Modified: 26 May 2026

    Summary: Malicious code in itc-actors-api (npm)

    Details: Source: amazon-inspector (22687e1f7601dde1753d3775925d62d040892631394937e56e9b9fba74fb85c6) The package contains callback.js which collects host identifiers and user information (os.hostname(), os.userInfo(), os.platform(), cwd) and transmits them via an HTTPS request. The file structures the collected data with fields like hostname, username, and cwd — the canonical reconnaissance-beacon shape used by dependency-confusion / supply-chain reconnaissance campaigns. The package name and 99.0.0 version (a high-version-number pattern typical of dependency-confusion attacks targeting internal package names) further corroborate malicious intent. Installing or loading this package leaks identifying information about the installer's machine to an external endpoint.

    Affected packages

    Package

    Name: itc-actors-api

    Purl: pkg:npm/itc-actors-api

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    99.0.0
    MAL-2026-4589 | CVE-DB