MAL-2026-6120

    Dashboard / Malicious Package / MAL-2026-6120

    MAL-2026-6120

    Published: 18 Jun 2026Last Modified: 18 Jun 2026

    Summary: Malicious code in @caspianph/storyteller (npm)

    Details: Source: amazon-inspector (3bd24daaa395f2e6bfae7c6e6f488a6e114b87e2606ec1bce7dcd4ab6a92f40a) The package ships setup.cjs containing heavily obfuscated JavaScript with hex-mangled identifiers (_0x32549a, _0x4b2b44, _0x78c349, _0x119ac2) typical of payload-hiding techniques. A file named setup.cjs in an npm package is structurally positioned to be invoked from a lifecycle hook (preinstall/install/postinstall) or required at module load. Legitimate npm packages do not obfuscate their install-time code; obfuscation in this position is overwhelmingly used to hide network beacons, credential reads, or dropper logic from casual inspection.

    Affected packages

    Package

    Name: @caspianph/storyteller

    Purl: pkg:npm/%40caspianph%2Fstoryteller

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.1.13
    MAL-2026-6120 | CVE-DB