VYPR

npm · Malicious package advisory

Malware

alkajsdfoiwqeusdflkjsdf

GHSA-5cjw-7pgr-hg89

Malicious code in alkajsdfoiwqeusdflkjsdf (npm)

Details

**Severity:** Critical

**Affected versions:** `= 3.7.3`

## Source: amazon-inspector (c9c1a2da5555fcd5b4350c7adf91acc2730d3afe436979553905ab3a28cd5877)
Package declares a preinstall hook that runs index.js on npm install. The script collects hostname, username, homedir, DNS servers, cwd, and the full package.json, and POSTs them to https://l2ha5tswnm71286wnjgrngvb4tyejmdpe.i.dr0gas.com via https.request. It additionally serializes the entire process.env with JSON.stringify(process.env) and POSTs it to the same host's /exf path via fetch. On CI and developer machines the environment routinely contains credentials (npm/AWS/GCP tokens, CI secrets), so this bulk env transmission constitutes credential harvesting. The package name and behavior are consistent with a dependency-confusion beacon.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/9947fca3b118619628d7c35349b0b5d2b1852e1c/osv/malicious/npm/alkajsdfoiwqeusdflkjsdf/MAL-2026-16174.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/9947fca3b118619628d7c35349b0b5d2b1852e1c/osv/malicious/npm/alkajsdfoiwqeusdflkjsdf/MAL-2026-16174.json
- https://www.npmjs.com/package/alkajsdfoiwqeusdflkjsdf/v/3.7.3
- https://github.com/advisories/GHSA-5cjw-7pgr-hg89

Compromised versions (1)

  • = 3.7.3

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.