CRITICAL npm Malware

Malicious code in spoint (npm)

MAL-2026-13725 · GHSA-72h3-pwwh-68cx

Published · Modified

Dependency scanning

Check whether spoint is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Description


__

Source: amazon-inspector (4c32e6b328bf731b6269e720e0fda2dec5264452ef04d406fde5296413424525)

Static keyword matches fired on the co-occurrence of tokens like 'curl', 'ping', 'POST', and 'GET' inside SDK/orchestrator source files (bin/room-orchestrator-boot.js, src/sdk/RoomOrchestrator.js, src/sdk/ServerAPI.js, src/sharding/RegionRouter.js). These are consistent with an orchestrator/routing SDK that performs latency probes and HTTP requests against its own service endpoints — the shape of a room/region networking client, not of an exfiltration primitive. No specific installer-side secret is shown being read (no ~/.aws, ~/.ssh, ~/.npmrc, env-var scraping, browser profile access), no hardcoded attacker C2 destination is named in evidence, and no lifecycle hook or top-level require-time execution path invoking these calls is demonstrated. Keyword co-occurrence in networking code is the shared shape of legitimate HTTP clients and cannot by itself establish exfiltration intent.

Source: ghsa-malware (4952c46b3a196baaec2d02092303fb499978b121dd6dac73c2f98e193985690c)

Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.

Ready to move

Start Securing

Free, no credit card | First findings in minutes