VYPR

npm · Malicious package advisory

Malware

com.db.autobahn.notification-center-electron

MAL-2026-15590

Malicious code in com.db.autobahn.notification-center-electron (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (4ae376efc666d8e07f356f9f3cbafe2dfc99e221a150ff96548db4a2b91bb452)
package.json declares preinstall and postinstall lifecycle scripts that automatically run curl on `npm install` to send installer identity (`whoami`, `hostname`, `$PWD`, timestamp) as query-string parameters to a long-random-label third-party host (`da9nfhavbsgte1dqq8fgrbb7fyfekc37i.cyowl.com`) over plain HTTP. The package name (`com.db.autobahn.notification-center-electron`) and implausibly high version (88.88.1) are consistent with a dependency-confusion lure targeting an internal scope; installing this package leaks host reconnaissance data to an external endpoint.

## Source: ossf-package-analysis (fe0ae07b99c275a092bcb2e4836aeb711a02f98def45f54f91bcf5ba38873807)
The OpenSSF Package Analysis project identified 'com.db.autobahn.notification-center-electron' @ 88.88.2 (npm) as malicious.

It is considered malicious because:

- The package executes one or more commands associated with malicious behavior.

Compromised versions (2)

  • 88.88.2
  • 88.88.1

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.