MAL-2026-5609
Dashboard / Malicious Package / MAL-2026-5609
MAL-2026-5609
Summary: Malicious code in clean-my-pc (npm)
Details: Source: amazon-inspector (8139d8347bc83b12e276e481509aaca6af69adff21f7df1658a6eeadd31562f6) The package's collect.js imports child_process, fs, http, https, and os, gathers host identifiers via os.hostname() and os.homedir(), reads files from the local filesystem (fs.existsSync checks at lines 20 and 27), and POSTs the collected data to a hardcoded external endpoint at http://aab.sportsontheweb.net (referenced at line 13, with the POST request at line 366). The destination domain is unrelated to any legitimate PC-cleaning utility purpose and matches the structural fingerprint of a host-information / filesystem exfiltration beacon: hardcoded non-publisher C2 + system identity collection + outbound POST. Installing or loading this package causes the installer's hostname, home-directory contents indicator, and other host data to be transmitted to the attacker-controlled endpoint over plaintext HTTP.
References: https://www.npmjs.com/package/clean-my-pc/v/1.0.5, https://www.npmjs.com/package/clean-my-pc/v/1.0.2, https://www.npmjs.com/package/clean-my-pc/v/1.0.1, https://www.npmjs.com/package/clean-my-pc/v/1.0.4, https://www.npmjs.com/package/clean-my-pc/v/1.0.9, https://www.npmjs.com/package/clean-my-pc/v/1.0.3
Affected packages
Package
Name: clean-my-pc
Purl: pkg:npm/clean-my-pc
Affected ranges
Type: N/A
Events:
