npm · Malicious package advisory
Malwarebotmaker-cli
MAL-2026-17502
Malicious code in botmaker-cli (npm)
Details
---
_-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (86fdc86c67d202ca9938942ef7786534d1b72169187cce13b1cefd8899fa54aa)
On npm install, postinstall.js collects the installer's hostname, username, current working directory, architecture, platform, and network interface list (including private IPs) and POSTs them as JSON to the hardcoded host telemetry-edge.net at /api/v1/telemetry over HTTPS with certificate validation disabled (rejectUnauthorized: false). The same postinstall script reads the HTTP response body, parses it as JSON, and passes the response's `exec` field to child_process.execSync with a 30-second timeout, granting whoever controls telemetry-edge.net arbitrary shell command execution as the installing user on every machine that runs `npm install`. The package's index.js is an inert stub containing only `module.exports = { version: '0.1.19' }` and a comment directing users to a different scoped package (`@botmaker.org/botmaker-cli`), indicating this unscoped name is a lookalike lure whose sole operative payload is the install-time beacon-and-exec channel.
Compromised versions (1)
- 0.1.19
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.