Note: This report is updated by a verification record
Malicious package due to data exfiltration to a hardcoded IP, command execution, suspicious install scripts, and few published versions.
The package is marked as malware by OSV: MAL-2026-1381 with source: amazon-inspector
Note: This report is updated by a verification record
The package exhibits multiple strong indicators of malicious behavior. The callback.js file contains code to collect sensitive system information (hostname, username, IP addresses, OS details, CI environment variables) and exfiltrate it to a hardcoded IP address (168.220.234.152) via HTTP POST/GET requests and DNS queries. The package.json file includes preinstall and postinstall scripts that execute callback.js, allowing arbitrary code execution during installation. The package also has very few published versions, which may indicate malicious intent. The combination of data exfiltration, command execution, and suspicious install scripts strongly suggests that this package is malicious.