MAL-2026-6184

    Dashboard / Malicious Package / MAL-2026-6184

    MAL-2026-6184

    Published: 19 Jun 2026Last Modified: 19 Jun 2026

    Summary: Malicious code in @qlab/component-intelligence (npm)

    Details: Source: amazon-inspector (9ad49caeee790003270d74c5b17a58d0cef6f04d881efe83b0f6c7e11515e934) package.json declares a preinstall hook (`"preinstall": "node index.js"`) that fires automatically on `npm install`. index.js requires os, dns, https, querystring, and the package's own package.json, then collects the installer's hostname (`os.hostname()`), username (`os.userInfo().username`), home directory (`os.homedir()`), configured DNS servers (`dns.getServers()`), current working directory, and the full contents of package.json, and POSTs them via HTTPS to the hardcoded webhook `https://eo1e4fhn1i67p8r.m.pipedream.net/`. This is the canonical dependency-confusion / recon-beacon shape: host identifiers and internal package metadata leave the machine unconditionally at install time to an attacker-controlled endpoint, giving the attacker reconnaissance data on internal package names, corporate hostnames, and user identities to fuel follow-on supply-chain attacks.

    Affected packages

    Package

    Name: @qlab/component-intelligence

    Purl: pkg:npm/%40qlab%2Fcomponent-intelligence

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    2.0.6
    MAL-2026-6184 | CVE-DB