Malicious code in spoint (npm)
MAL-2026-13725 · GHSA-72h3-pwwh-68cx
Published · Modified
Dependency scanning
Check whether spoint is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Description
__
Source: amazon-inspector (4c32e6b328bf731b6269e720e0fda2dec5264452ef04d406fde5296413424525)
Static keyword matches fired on the co-occurrence of tokens like 'curl', 'ping', 'POST', and 'GET' inside SDK/orchestrator source files (bin/room-orchestrator-boot.js, src/sdk/RoomOrchestrator.js, src/sdk/ServerAPI.js, src/sharding/RegionRouter.js). These are consistent with an orchestrator/routing SDK that performs latency probes and HTTP requests against its own service endpoints — the shape of a room/region networking client, not of an exfiltration primitive. No specific installer-side secret is shown being read (no ~/.aws, ~/.ssh, ~/.npmrc, env-var scraping, browser profile access), no hardcoded attacker C2 destination is named in evidence, and no lifecycle hook or top-level require-time execution path invoking these calls is demonstrated. Keyword co-occurrence in networking code is the shared shape of legitimate HTTP clients and cannot by itself establish exfiltration intent.
Source: ghsa-malware (4952c46b3a196baaec2d02092303fb499978b121dd6dac73c2f98e193985690c)
Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
References
- ADVISORY https://github.com/advisories/GHSA-72h3-pwwh-68cx
- PACKAGE https://www.npmjs.com/package/spoint/v/0.1.699
- PACKAGE https://www.npmjs.com/package/spoint/v/0.1.698
- PACKAGE https://www.npmjs.com/package/spoint/v/0.1.696
- PACKAGE https://www.npmjs.com/package/spoint/v/0.1.697
- PACKAGE https://www.npmjs.com/package/spoint/v/0.1.700
- PACKAGE https://www.npmjs.com/package/spoint/v/0.1.695
Ready to move
Start Securing
Free, no credit card | First findings in minutes