npm · Malicious package advisory
Malware@medisend/webview-bridge
GHSA-4v36-qjgj-x7xf
Malicious code in @medisend/webview-bridge (npm)
Details
**Severity:** Critical **Affected versions:** `= 0.0.1-security-research` ## Source: amazon-inspector (ddf4b396c306b8f8d090b929c265b8ae848c75e53b9750d6f68800a4deefe9a2) package.json declares a postinstall lifecycle script that runs curl to https://webhook.site/74ed1be3-96d6-48c3-932b-6b1dbabaff97 with query parameters populated from $(whoami), $(hostname), $(pwd), $(ls -la), and $(node -v). On every npm install the installer's username, hostname, working directory, a directory listing of the install location, and Node.js version are sent to a third-party webhook.site collector controlled by whoever provisioned that endpoint. The package publishes under the @medisend scope and its description states a dependency-confusion test referencing a third-party VDP; an installer whose internal tooling resolves the public registry version instead of an internal @medisend package will trigger this exfiltration automatically. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/72e5d8219b286d7332c4ad2364b87986138cf34c/osv/malicious/npm/@medisend/webview-bridge/MAL-2026-14424.json)) **References:** - https://github.com/ossf/malicious-packages/blob/72e5d8219b286d7332c4ad2364b87986138cf34c/osv/malicious/npm/@medisend/webview-bridge/MAL-2026-14424.json - https://www.npmjs.com/package/@medisend/webview-bridge/v/0.0.1-security-research - https://www.npmjs.com/package/@medisend/webview-bridge/v/0.0.2-security-research - https://github.com/ossf/malicious-packages/blob/0c1b211c2970f9a07291c293eb800c200f0ed15e/osv/malicious/npm/@medisend/webview-bridge/MAL-2026-14424.json - https://github.com/advisories/GHSA-4v36-qjgj-x7xf
Compromised versions (1)
- = 0.0.1-security-research
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.