VYPR

npm · Malicious package advisory

Malware

@medisend/auth

GHSA-3x6g-8hj7-q568

Malicious code in @medisend/auth (npm)

Details

**Severity:** Critical

**Affected versions:** `= 0.0.1-security-research`

## Source: amazon-inspector (8363fc41a00733469f69df79f45ecebd190ac85d16d8cbdd48a61fe5bfb67003)
package.json declares a postinstall lifecycle script that runs `curl` against https://webhook.site/74ed1be3-96d6-48c3-932b-6b1dbabaff97 with the installer's hostname appended as a query parameter (`?pkg=medisend-auth-$(hostname)`). On `npm install`, this fires automatically and transmits an installer-identifying host indicator to a third-party anonymous collector endpoint controlled by whoever holds the webhook.site token. The @medisend/* scope and the package name pattern are consistent with dependency-confusion beaconing against an internal namespace.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/72e5d8219b286d7332c4ad2364b87986138cf34c/osv/malicious/npm/@medisend/auth/MAL-2026-14421.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/72e5d8219b286d7332c4ad2364b87986138cf34c/osv/malicious/npm/@medisend/auth/MAL-2026-14421.json
- https://www.npmjs.com/package/@medisend/auth/v/0.0.1-security-research
- https://github.com/advisories/GHSA-3x6g-8hj7-q568

Compromised versions (1)

  • = 0.0.1-security-research

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.