VYPR

npm · Malicious package advisory

Malware

fuels-core

MAL-2026-15592

Malicious code in fuels-core (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (c632848960231dec103d878a13a714e057a5922edcc0398884b6fd6d621e0971)
The package's bin script (bin/cli.js) collects `whoami`, `os.hostname()`, and `os.platform()` and POSTs them along with the package name to a hardcoded Cloudflare Workers URL (https://oobme.kunalsharma0553.workers.dev/r/7bq6fz3l15r9) with no configuration or opt-out. The bin is exposed as `generate-schema-viem`, and the package name `fuels-core` resembles the Fuel ecosystem's `fuels` package, consistent with typosquat/dependency-confusion reconnaissance targeting installers who resolve or invoke this package (e.g., via `npx`). The package.json description openly states its purpose is to POST package name and whoami to an OOB callback.

## Source: ossf-package-analysis (d21bb4c8fac5120e8d1c6227bd7248f35ddb633bcb3c7ca08427b964cdb0ee93)
The OpenSSF Package Analysis project identified 'fuels-core' @ 1.0.0 (npm) as malicious.

It is considered malicious because:

- The package communicates with a domain associated with malicious activity.

- The package executes one or more commands associated with malicious behavior.

Compromised versions (1)

  • 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.