VYPR

npm · Malicious package advisory

Malware

@prime0/alanced-match

GHSA-wr38-cc44-847g

Malicious code in @prime0/alanced-match (npm)

Details

**Severity:** Critical

**Affected versions:** `= 1.0.0`

## Source: amazon-inspector (53d49bf28eb233bca0591b32c11b411d1c10b8e8f978d1b76c6df2e6a00772f3)
The package @prime0/alanced-match is a 1-character-drop typosquat of balanced-match. Its postinstall.js runs automatically on npm install and POSTs a host fingerprint (hostname, username, platform, arch, cwd, node version, pid, non-internal IP addresses, uptime, package name) to the hardcoded bare-IP endpoint http://69.48.229.140:8080/b. Its main entry index.js opens a require-time HTTP polling channel to the same host, retrieves JSON commands from /c every 30 seconds (with 10-minute re-beacons), executes them via child_process.exec, and posts stdout/stderr back to /r — providing full remote code execution on the installer's machine. A source comment self-identifies the code as a 'Minimal stealth agent' and 'typosquat'.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a03f98a1b88f3ad29d120e41e5d5e14f25d25979/osv/malicious/npm/@prime0/alanced-match/MAL-2026-16204.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/a03f98a1b88f3ad29d120e41e5d5e14f25d25979/osv/malicious/npm/@prime0/alanced-match/MAL-2026-16204.json
- https://www.npmjs.com/package/@prime0/alanced-match/v/1.0.0
- https://github.com/advisories/GHSA-wr38-cc44-847g

Compromised versions (1)

  • = 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.