VYPR

npm · Malicious package advisory

Malware

csa-mfa

GHSA-gqh9-2j3v-c5g6

Malicious code in csa-mfa (npm)

Details

**Severity:** Critical

**Affected versions:** `= 1.1.15`

## Source: amazon-inspector (959d2728ff38a804033ca7e07235b3a14bce65bd0e948077ba148a53c6cccff9)
package.json declares a preinstall script that runs wget against http://169.58.142.14:8080/ with query parameters populated by shell command substitution of whoami, ls, and hostname. On npm install this automatically transmits the installer's username, current-directory listing, and hostname to a hardcoded bare-IP HTTP endpoint unrelated to any legitimate publisher infrastructure. There is no functional package purpose served by this behavior.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/9947fca3b118619628d7c35349b0b5d2b1852e1c/osv/malicious/npm/csa-mfa/MAL-2026-16175.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/9947fca3b118619628d7c35349b0b5d2b1852e1c/osv/malicious/npm/csa-mfa/MAL-2026-16175.json
- https://www.npmjs.com/package/csa-mfa/v/1.1.15
- https://www.npmjs.com/package/csa-mfa/v/1.1.16
- https://github.com/advisories/GHSA-gqh9-2j3v-c5g6

Compromised versions (1)

  • = 1.1.15

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.