VYPR

npm · Malicious package advisory

Malware

@inpeek/odata

MAL-2026-17542

Malicious code in @inpeek/odata (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (dad085b4b3e089d6a6d4e6812c66a8b45f10d40bc4ab39ea7bd0ce850d17ed4b)
@inpeek/[email protected] is a dependency-confusion placeholder published to the public npm registry on the unregistered @inpeek scope with an inflated version (99.99.100) designed to outrank any internal release of the same name. The package.json declares a postinstall lifecycle hook that executes ping.js on `npm install`. ping.js performs an unconditional HTTPS GET to the hardcoded collector URL https://webhook.site/bec9d4b2-8f49-451e-84be-2681cb91ebf2, passing the installer's hostname (os.hostname()), platform (os.platform()), and Node.js version (process.version) as query parameters. index.js throws on require, so any accidental consumer breaks loudly after the postinstall beacon has already fired. The package self-labels as a bug-bounty research placeholder, but the install-time dataflow — automatic transmission of installer host identifiers to a third-party collector the installer did not opt into — is the dependency-confusion exploitation shape and reaches any installer whose tooling resolves @inpeek/* from the public registry.

Compromised versions (4)

  • 99.99.102
  • 99.99.100
  • 99.99.99
  • 99.99.101

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.