MAL-2026-6789

    Dashboard / Malicious Package / MAL-2026-6789

    MAL-2026-6789

    Published: 2 Jul 2026Last Modified: 9 Jul 2026

    Summary: Malicious code in @checkrhq/adjudication-api-client (npm)

    Details: Source: amazon-inspector (8c52d9987ace09f0c48d8b0661bd1fcd3cf4e7e701b5e515810c7f32d99086cf) package.json declares a preinstall lifecycle script that runs `curl` to POST installer reconnaissance data — hostname, current user (whoami), working directory, and uid/gid (id) — to a hardcoded webhook.site collector endpoint on every `npm install`. The package is published under an @checkrhq scope impersonating Checkr Inc. (author email uses checkr.com; description states 'This package is for testing only.') and ships no functional code, matching the canonical dependency-confusion beacon pattern targeting an organization's internal package namespace. Installing this package causes automatic outbound transmission of host and user identifiers to an anonymous third-party collector controlled by the publisher. Source: ossf-package-analysis (dc8d5c39d401d053978bb8f17234bc79db730d15b55634319f239baf32dc9b0b) The OpenSSF Package Analysis project identified '@checkrhq/adjudication-api-client' @ 0.0.2 (npm) as malicious. It is considered malicious because: - The package executes one or more commands associated with malicious behavior.

    Affected packages

    Package

    Name: @checkrhq/adjudication-api-client

    Purl: pkg:npm/%40checkrhq/adjudication-api-client

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.0.2