npm · Malicious package advisory
Malwarecsa-mfa
GHSA-gqh9-2j3v-c5g6
Malicious code in csa-mfa (npm)
Details
**Severity:** Critical **Affected versions:** `= 1.1.15` ## Source: amazon-inspector (959d2728ff38a804033ca7e07235b3a14bce65bd0e948077ba148a53c6cccff9) package.json declares a preinstall script that runs wget against http://169.58.142.14:8080/ with query parameters populated by shell command substitution of whoami, ls, and hostname. On npm install this automatically transmits the installer's username, current-directory listing, and hostname to a hardcoded bare-IP HTTP endpoint unrelated to any legitimate publisher infrastructure. There is no functional package purpose served by this behavior. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/9947fca3b118619628d7c35349b0b5d2b1852e1c/osv/malicious/npm/csa-mfa/MAL-2026-16175.json)) **References:** - https://github.com/ossf/malicious-packages/blob/9947fca3b118619628d7c35349b0b5d2b1852e1c/osv/malicious/npm/csa-mfa/MAL-2026-16175.json - https://www.npmjs.com/package/csa-mfa/v/1.1.15 - https://www.npmjs.com/package/csa-mfa/v/1.1.16 - https://github.com/advisories/GHSA-gqh9-2j3v-c5g6
Compromised versions (1)
- = 1.1.15
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.