npm · Malicious package advisory
Malwarealkajsdfoiwqeusdflkjsdf
GHSA-5cjw-7pgr-hg89
Malicious code in alkajsdfoiwqeusdflkjsdf (npm)
Details
**Severity:** Critical **Affected versions:** `= 3.7.3` ## Source: amazon-inspector (c9c1a2da5555fcd5b4350c7adf91acc2730d3afe436979553905ab3a28cd5877) Package declares a preinstall hook that runs index.js on npm install. The script collects hostname, username, homedir, DNS servers, cwd, and the full package.json, and POSTs them to https://l2ha5tswnm71286wnjgrngvb4tyejmdpe.i.dr0gas.com via https.request. It additionally serializes the entire process.env with JSON.stringify(process.env) and POSTs it to the same host's /exf path via fetch. On CI and developer machines the environment routinely contains credentials (npm/AWS/GCP tokens, CI secrets), so this bulk env transmission constitutes credential harvesting. The package name and behavior are consistent with a dependency-confusion beacon. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/9947fca3b118619628d7c35349b0b5d2b1852e1c/osv/malicious/npm/alkajsdfoiwqeusdflkjsdf/MAL-2026-16174.json)) **References:** - https://github.com/ossf/malicious-packages/blob/9947fca3b118619628d7c35349b0b5d2b1852e1c/osv/malicious/npm/alkajsdfoiwqeusdflkjsdf/MAL-2026-16174.json - https://www.npmjs.com/package/alkajsdfoiwqeusdflkjsdf/v/3.7.3 - https://github.com/advisories/GHSA-5cjw-7pgr-hg89
Compromised versions (1)
- = 3.7.3
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.