npm · Malicious package advisory
Malwarecsa-mfa
MAL-2026-16175
Malicious code in csa-mfa (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (959d2728ff38a804033ca7e07235b3a14bce65bd0e948077ba148a53c6cccff9) package.json declares a preinstall script that runs wget against http://169.58.142.14:8080/ with query parameters populated by shell command substitution of whoami, ls, and hostname. On npm install this automatically transmits the installer's username, current-directory listing, and hostname to a hardcoded bare-IP HTTP endpoint unrelated to any legitimate publisher infrastructure. There is no functional package purpose served by this behavior.
Compromised versions (2)
- 1.1.15
- 1.1.16
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.