VYPR

npm · Malicious package advisory

Malware

terminal-formatter

MAL-2026-2911

Malicious code in terminal-formatter (npm)

Details

terminal-formatter is a malicious npm package that when installed (postinstall-hook) or imported sends local env variables, files and bash history to https://ghostraper[.]top and registers a new ssh key in .ssh/authorized_keys.

---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (ab93869d5c21b5d8424c3c527825b2f0051e5736740429dd67e71403474ee281)
The package terminal-formatter was found to contain malicious code.