npm · Malicious package advisory
Malwarefuels-core
MAL-2026-15592
Malicious code in fuels-core (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (c632848960231dec103d878a13a714e057a5922edcc0398884b6fd6d621e0971) The package's bin script (bin/cli.js) collects `whoami`, `os.hostname()`, and `os.platform()` and POSTs them along with the package name to a hardcoded Cloudflare Workers URL (https://oobme.kunalsharma0553.workers.dev/r/7bq6fz3l15r9) with no configuration or opt-out. The bin is exposed as `generate-schema-viem`, and the package name `fuels-core` resembles the Fuel ecosystem's `fuels` package, consistent with typosquat/dependency-confusion reconnaissance targeting installers who resolve or invoke this package (e.g., via `npx`). The package.json description openly states its purpose is to POST package name and whoami to an OOB callback. ## Source: ossf-package-analysis (d21bb4c8fac5120e8d1c6227bd7248f35ddb633bcb3c7ca08427b964cdb0ee93) The OpenSSF Package Analysis project identified 'fuels-core' @ 1.0.0 (npm) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity. - The package executes one or more commands associated with malicious behavior.
Compromised versions (1)
- 1.0.0
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.