npm · Malicious package advisory
Malware@gusmano/reext
MAL-2026-3684
Malicious code in @gusmano/reext (npm)
Details
---
_-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (498a21b60dcdfe236ea0b1683e1ec64aa091643b6ad562c3845757eed79660d8)
The npm preinstall lifecycle script (dist/scripts/preinstall.js, wired via package.json "preinstall": "node./dist/scripts/preinstall.js") reads the installer's ~/.gitconfig via iniparser.parseSync(home_dir+'/.gitconfig') and the OS username via os.userInfo().username, then issues an HTTPS GET to the hardcoded endpoint https://2tak.l.serverhost.name:1962/mobile/reext with osname, gitname, and gitemail supplied as query parameters. The code explicitly branches on `if (osname === 'xmarcgusmano') { server = 'http://localhost:1962' } else { server = 'https://2tak.l.serverhost.name:1962' }`, confirming that the remote-host path fires for every installer that is not the author's own machine — a deliberate exfiltration path gated by the author's own username. The destination is not a documented vendor endpoint; it is an author-controlled third-party host the installer did not opt into. Separately, dist/scripts/postinstall.js resolves `path.resolve(__dirname, '../../package.json')` (the consuming project's own package.json relative to node_modules/@gusmano/reext/dist/scripts/) and rewrites it, deleting scripts.dev/build/test/watch/coverage, the entire `scripts` key, `eslintConfig`, `devDependencies`, and `dependencies`, then rm -rf's several dist subfolders — destructive, unauthorized mutation of the installer's project files. The combination (silent install-time exfiltration of personal identity data to an author-controlled host plus destructive rewrite of the consumer's manifest) is unambiguously harmful to installers.
Compromised versions (34)
- 0.0.104
- 0.0.166
- 0.0.216
- 0.0.150
- 0.0.148
- 0.0.218
- 0.0.197
- 0.0.276
- 0.0.92
- 0.0.98
- 0.0.317
- 0.0.169
- 0.0.209
- 0.0.250
- 0.0.236
- 0.0.121
- 0.0.198
- 0.0.128
- 0.0.190
- 0.0.352
- 0.0.223
- 0.0.261
- 0.0.315
- 0.0.235
- 0.0.251
- 0.0.473
- 0.0.358
- 0.0.188
- 0.0.390
- 0.0.237
- 0.0.255
- 0.0.222
- 0.0.324
- 0.0.346
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.