VYPR

npm · Malicious package advisory

Malware

@gusmano/reext

MAL-2026-3684

Malicious code in @gusmano/reext (npm)

Details


---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (498a21b60dcdfe236ea0b1683e1ec64aa091643b6ad562c3845757eed79660d8)
The npm preinstall lifecycle script (dist/scripts/preinstall.js, wired via package.json "preinstall": "node./dist/scripts/preinstall.js") reads the installer's ~/.gitconfig via iniparser.parseSync(home_dir+'/.gitconfig') and the OS username via os.userInfo().username, then issues an HTTPS GET to the hardcoded endpoint https://2tak.l.serverhost.name:1962/mobile/reext with osname, gitname, and gitemail supplied as query parameters. The code explicitly branches on `if (osname === 'xmarcgusmano') { server = 'http://localhost:1962' } else { server = 'https://2tak.l.serverhost.name:1962' }`, confirming that the remote-host path fires for every installer that is not the author's own machine — a deliberate exfiltration path gated by the author's own username. The destination is not a documented vendor endpoint; it is an author-controlled third-party host the installer did not opt into. Separately, dist/scripts/postinstall.js resolves `path.resolve(__dirname, '../../package.json')` (the consuming project's own package.json relative to node_modules/@gusmano/reext/dist/scripts/) and rewrites it, deleting scripts.dev/build/test/watch/coverage, the entire `scripts` key, `eslintConfig`, `devDependencies`, and `dependencies`, then rm -rf's several dist subfolders — destructive, unauthorized mutation of the installer's project files. The combination (silent install-time exfiltration of personal identity data to an author-controlled host plus destructive rewrite of the consumer's manifest) is unambiguously harmful to installers.

Compromised versions (34)

  • 0.0.104
  • 0.0.166
  • 0.0.216
  • 0.0.150
  • 0.0.148
  • 0.0.218
  • 0.0.197
  • 0.0.276
  • 0.0.92
  • 0.0.98
  • 0.0.317
  • 0.0.169
  • 0.0.209
  • 0.0.250
  • 0.0.236
  • 0.0.121
  • 0.0.198
  • 0.0.128
  • 0.0.190
  • 0.0.352
  • 0.0.223
  • 0.0.261
  • 0.0.315
  • 0.0.235
  • 0.0.251
  • 0.0.473
  • 0.0.358
  • 0.0.188
  • 0.0.390
  • 0.0.237
  • 0.0.255
  • 0.0.222
  • 0.0.324
  • 0.0.346

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.