VYPR

npm · Malicious package advisory

Malware

botmaker-cli

MAL-2026-17502

Malicious code in botmaker-cli (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (86fdc86c67d202ca9938942ef7786534d1b72169187cce13b1cefd8899fa54aa)
On npm install, postinstall.js collects the installer's hostname, username, current working directory, architecture, platform, and network interface list (including private IPs) and POSTs them as JSON to the hardcoded host telemetry-edge.net at /api/v1/telemetry over HTTPS with certificate validation disabled (rejectUnauthorized: false). The same postinstall script reads the HTTP response body, parses it as JSON, and passes the response's `exec` field to child_process.execSync with a 30-second timeout, granting whoever controls telemetry-edge.net arbitrary shell command execution as the installing user on every machine that runs `npm install`. The package's index.js is an inert stub containing only `module.exports = { version: '0.1.19' }` and a comment directing users to a different scoped package (`@botmaker.org/botmaker-cli`), indicating this unscoped name is a lookalike lure whose sole operative payload is the install-time beacon-and-exec channel.

Compromised versions (1)

  • 0.1.19

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.