VYPR

npm · Malicious package advisory

Malware

@medisend/webview-bridge

MAL-2026-14424

Malicious code in @medisend/webview-bridge (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (ddf4b396c306b8f8d090b929c265b8ae848c75e53b9750d6f68800a4deefe9a2)
package.json declares a postinstall lifecycle script that runs curl to https://webhook.site/74ed1be3-96d6-48c3-932b-6b1dbabaff97 with query parameters populated from $(whoami), $(hostname), $(pwd), $(ls -la), and $(node -v). On every npm install the installer's username, hostname, working directory, a directory listing of the install location, and Node.js version are sent to a third-party webhook.site collector controlled by whoever provisioned that endpoint. The package publishes under the @medisend scope and its description states a dependency-confusion test referencing a third-party VDP; an installer whose internal tooling resolves the public registry version instead of an internal @medisend package will trigger this exfiltration automatically.

## Source: ossf-package-analysis (bcefced9c742cce25a3c42fdb4cd5c9f2545184e7b661fff98f362ba0a566ce1)
The OpenSSF Package Analysis project identified '@medisend/webview-bridge' @ 0.0.2-security-research (npm) as malicious.

It is considered malicious because:

- The package executes one or more commands associated with malicious behavior.

Compromised versions (2)

  • 0.0.1-security-research
  • 0.0.2-security-research

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.