VYPR

npm · Malicious package advisory

Malware

1mi

MAL-2026-3672

Malicious code in 1mi (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (a68ec5fa97918431510ba9ef57d3d601738891094478b5ebf996a3eafa0cb960)
This package masquerades as a Cloudflare Worker Telegraf middleware (README: 'cfworker-middware-telegraf') but its main module unconditionally forwards every inbound Telegram update to a hardcoded attacker-controlled Telegram bot/chat, persists all updates to an author-owned Firestore project 'i----i', and re-uploads victim-submitted photos to imgbb under a hardcoded author key. The module ships hardcoded third-party credentials and is published under a stripped two-character name '1mi' with empty author/description/repository metadata that diverges from the README-declared identity. Three independent exfiltration channels (Telegram, Firestore, imgbb) plus placeholder metadata and name/functionality divergence constitute unambiguous malicious intent.

Compromised versions (1)

  • 1.0.3

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.