npm · Malicious package advisory
Malwarezeal-rq-hooks
GHSA-62m8-8rfw-gv5v
Malicious code in zeal-rq-hooks (npm)
Details
**Severity:** Critical **Affected versions:** `= 0.0.0` ## Source: amazon-inspector (dcf7e926ec85f72f362263a19d4f99c4b215ddd94ed4454c669c3387cacee164) The package includes canary.js which imports os/http/https and, at line 123, POSTs a JSON body containing os.hostname(), os.userInfo(), process.platform, node/npm version, and cwd to the hardcoded endpoint https://npm-canary.aveliscare.com. The hostname is not associated with the npm registry or a documented publisher and is embedded directly in the package's own shipped code. The collected fields (hostname, username, platform, cwd) are host-identifying reconnaissance data, and the network destination is not user-configurable in the flagged code path. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/2e378bd92123960dd5c4606447d823e21c81f267/osv/malicious/npm/zeal-rq-hooks/MAL-2026-13742.json)) **References:** - https://github.com/ossf/malicious-packages/blob/2e378bd92123960dd5c4606447d823e21c81f267/osv/malicious/npm/zeal-rq-hooks/MAL-2026-13742.json - https://www.npmjs.com/package/zeal-rq-hooks/v/0.0.0 - https://github.com/advisories/GHSA-62m8-8rfw-gv5v
Compromised versions (1)
- = 0.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.