MAL-2026-5449
Dashboard / Malicious Package / MAL-2026-5449
MAL-2026-5449
Summary: Malicious code in morningstar-design-system (npm)
Details: Source: amazon-inspector (18591ac1a5cb5ca3d11e07bde38f230dccc530bb4614d45f9be1f547677a2c9e) On `npm install`, the package's `preinstall` lifecycle script runs `wget` against a hardcoded bare-IP HTTP endpoint, passing the output of `id`, `pwd`, `hostname`, and `ip a` as URL query parameters. This leaks the installing user's username/UID/GID, working directory, hostname, and full network interface configuration to an attacker-controlled host automatically, before any other code runs. The package name targets Morningstar's organizational namespace and is published at an absurd `99.0.1` version — the canonical dependency-confusion shape designed to override an internal package of the same name. README self-identifies as a dependency-confusion PoC. Whether labeled research or not, the published artifact actively exfiltrates installer data to a third-party IP and is unsafe to install in any environment.
References: https://www.npmjs.com/package/morningstar-design-system/v/99.0.1, https://www.npmjs.com/package/morningstar-design-system/v/99.0.2, https://www.npmjs.com/package/morningstar-design-system/v/99.0.0
Affected packages
Package
Name: morningstar-design-system
Purl: pkg:npm/morningstar-design-system
Affected ranges
Type: N/A
Events:
