MAL-2026-6090

    Dashboard / Malicious Package / MAL-2026-6090

    MAL-2026-6090

    Published: 18 Jun 2026Last Modified: 18 Jun 2026

    Summary: Malicious code in data-utils-bcf2 (npm)

    Details: Source: amazon-inspector (52e6ddf4cbc1a035918a5bd136c865ff526f430db21268d75d3c90fa74196fdf) The package declares a postinstall lifecycle hook ("postinstall": "node run.js" in package.json) that automatically executes run.js on install. run.js imports os, fs, http, https, and child_process, collects host identifying information (os.hostname(), os.platform()), reads files from disk (fs.readFileSync, fs.existsSync), and issues multiple POST requests over HTTP/HTTPS (run.js lines 134, 137, 348, 355). The combination of automatic install-time execution, host fingerprinting, filesystem reads, and outbound POSTs is the canonical install-time exfiltration shape. Installing this package on a developer machine or CI runner will run the reconnaissance and exfiltration code without user interaction.

    Affected packages

    Package

    Name: data-utils-bcf2

    Purl: pkg:npm/data-utils-bcf2

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.0.0