CRITICAL npm Malware

Malicious code in faceplate-docs (npm)

MAL-2024-2355

Published · Modified

Dependency scanning

Check whether faceplate-docs is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Description


__

Source: amazon-inspector (f5198954164869432a0fda9f3f723c1db53531ab2f73db84523e6f62946cf420)

faceplate-docs@99.9.10 runs index.js from a postinstall hook that collects the installer's OS username, current working directory, hostname, and local IPv4 address and POSTs them as JSON to a hardcoded anonymous collector at https://webhook.site/f9bff304-3053-4d54-be05-86537267514a. The beacon fires automatically on npm install without any user interaction. The package name plus implausibly high version (99.9.10) and the recon-only payload are characteristic of a dependency-confusion probe designed to identify internal build environments that mistakenly resolve a private package name from the public registry.

Ready to move

Start Securing

Free, no credit card | First findings in minutes