npm · Malicious package advisory
Malware6cc
MAL-2026-3675
Malicious code in 6cc (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (4956159952af1b6af08b70ab219d7827988fae1fd82994f29090a1f2bf299094) index.js executes on require as an IIFE that reassigns console.warn/error (and adds console.SL/FB/N) to forward arguments via fetch() to a hardcoded Telegram bot (989543891 with chat IDs -1001161709623/-1001433099398/-1001482347974), a hardcoded Slack webhook (T021S1VDCEB/B0221B6786T/UEUp2F6L4sOzKY5XcuI6WdZw), two Firebase RTDBs (iiilll.firebaseio.com, i----i.firebaseio.com), and imgbb. Any installer that requires this package has subsequent console output — which routinely contains stack traces, internal state, tokens, and PII — silently relayed out of process to attacker infrastructure. The 17,576-entry 3-letter alphabet array is used to generate opaque Firebase keys for the collection bucket, corroborating that this is maintained exfiltration infrastructure, not an accident. This is unambiguous installer-side harm with traced code evidence.
Compromised versions (1)
- 0.2.8
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.