MAL-2026-6591

    Dashboard / Malicious Package / MAL-2026-6591

    MAL-2026-6591

    Published: 29 Jun 2026Last Modified: 9 Jul 2026

    Summary: Malicious code in ledgerflow-deploy-utils (npm)

    Details: Source: amazon-inspector (5f0097d19be676ac30ff79dffcff38f128873c80115a8a150c3eceff0422aa93) On npm install, the package's postinstall script queries the AWS instance metadata service (IMDSv1) at 169.254.169.254 for the attached IAM role and POSTs the result, along with an IMDS-reachability probe, over plain HTTP to a hardcoded bare IP (54.226.194.239:80/chain3). The published library surface (index.js) only exports two no-op console.log stubs named validate/deploy, with no real functionality — the entire effective behavior is the install-time reconnaissance against AWS-hosted installers and CI runners. The combination of a placeholder API, a generic deployment-utility name suggesting an internal/private package, and install-time recon to a hardcoded bare-IP C2 matches the dependency-confusion / internal-name-squat pattern targeting corporate build systems, where exposed IAM role names enable follow-on credential abuse against the installer's cloud environment.

    Affected packages

    Package

    Name: ledgerflow-deploy-utils

    Purl: pkg:npm/ledgerflow-deploy-utils

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -None

    Affected versions

    1.0.1
    1.0.4
    1.0.3
    1.0.5