CRITICAL npm Malware

Malicious code in store-locator-widget (npm)

MAL-2026-12804

Published · Modified

Description


__

Source: amazon-inspector (1b2ffc9f3972c8313fe78eaac2412cc8e46a693d149404736a089a18596ff7f5)

store-locator-widget@9999.0.0 ships an empty library body (index.js exports {}) and a preinstall hook (node callback.js) that, on npm install, collects the installer's hostname, username, current working directory, configured npm registry, and CI project-slug environment variables (GITHUB_REPOSITORY, CI_PROJECT_PATH, BUILD_REPOSITORY_NAME, and similar) and transmits them as query-string parameters via HTTP GET to a hardcoded bare-IP endpoint at http://75.119.137.232:31337/depconfuse. The version number 9999.0.0, the placeholder description, the empty module body, and the /depconfuse URL path together match the dependency-confusion reconnaissance probe pattern: the package delivers no advertised functionality and its sole install-time effect is to leak information about the installer's internal package namespace and build environment to an attacker-controlled destination.

Ready to move

Start Securing

Free, no credit card | First findings in minutes