VYPR

npm · Malicious package advisory

Malware

whs4_ued

GHSA-v5xx-cpfg-4c3j

Malicious code in whs4_ued (npm)

Details

**Severity:** Critical

**Affected versions:** `= 1.0.0`

## Source: amazon-inspector (6be723a2156cdb77cc97a0afb9ee15e4d50928a1924cd6cde69bcaacf2707a8b)
On npm install, the package's postinstall hook runs `node index.js`, which POSTs installer host information — the absolute path of the package file (leaking the OS username and home directory layout), Node.js version, platform, and architecture — to a hardcoded Discord webhook at discord.com/api/webhooks/1530599209269465319/. The webhook token is assembled via string concatenation at the call site to evade naive string matching. The destination is attacker-controlled and unrelated to the package's stated educational typo-catcher purpose, and there is no consent gate.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/e48a2ed516f973d5e1ccb9fbc7a6f18c7f58032c/osv/malicious/npm/whs4_ued/MAL-2026-13743.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/e48a2ed516f973d5e1ccb9fbc7a6f18c7f58032c/osv/malicious/npm/whs4_ued/MAL-2026-13743.json
- https://www.npmjs.com/package/whs4_ued/v/1.0.0
- https://github.com/advisories/GHSA-v5xx-cpfg-4c3j

Compromised versions (1)

  • = 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.