npm · Malicious package advisory
Malwarecom.db.autobahn.notification-center-electron
MAL-2026-15590
Malicious code in com.db.autobahn.notification-center-electron (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (4ae376efc666d8e07f356f9f3cbafe2dfc99e221a150ff96548db4a2b91bb452) package.json declares preinstall and postinstall lifecycle scripts that automatically run curl on `npm install` to send installer identity (`whoami`, `hostname`, `$PWD`, timestamp) as query-string parameters to a long-random-label third-party host (`da9nfhavbsgte1dqq8fgrbb7fyfekc37i.cyowl.com`) over plain HTTP. The package name (`com.db.autobahn.notification-center-electron`) and implausibly high version (88.88.1) are consistent with a dependency-confusion lure targeting an internal scope; installing this package leaks host reconnaissance data to an external endpoint. ## Source: ossf-package-analysis (fe0ae07b99c275a092bcb2e4836aeb711a02f98def45f54f91bcf5ba38873807) The OpenSSF Package Analysis project identified 'com.db.autobahn.notification-center-electron' @ 88.88.2 (npm) as malicious. It is considered malicious because: - The package executes one or more commands associated with malicious behavior.
Compromised versions (2)
- 88.88.2
- 88.88.1
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.