npm · Malicious package advisory
Malware@prime0/alanced-match
GHSA-wr38-cc44-847g
Malicious code in @prime0/alanced-match (npm)
Details
**Severity:** Critical **Affected versions:** `= 1.0.0` ## Source: amazon-inspector (53d49bf28eb233bca0591b32c11b411d1c10b8e8f978d1b76c6df2e6a00772f3) The package @prime0/alanced-match is a 1-character-drop typosquat of balanced-match. Its postinstall.js runs automatically on npm install and POSTs a host fingerprint (hostname, username, platform, arch, cwd, node version, pid, non-internal IP addresses, uptime, package name) to the hardcoded bare-IP endpoint http://69.48.229.140:8080/b. Its main entry index.js opens a require-time HTTP polling channel to the same host, retrieves JSON commands from /c every 30 seconds (with 10-minute re-beacons), executes them via child_process.exec, and posts stdout/stderr back to /r — providing full remote code execution on the installer's machine. A source comment self-identifies the code as a 'Minimal stealth agent' and 'typosquat'. --- Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a03f98a1b88f3ad29d120e41e5d5e14f25d25979/osv/malicious/npm/@prime0/alanced-match/MAL-2026-16204.json)) **References:** - https://github.com/ossf/malicious-packages/blob/a03f98a1b88f3ad29d120e41e5d5e14f25d25979/osv/malicious/npm/@prime0/alanced-match/MAL-2026-16204.json - https://www.npmjs.com/package/@prime0/alanced-match/v/1.0.0 - https://github.com/advisories/GHSA-wr38-cc44-847g
Compromised versions (1)
- = 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.