CRITICAL npm Malware

Malicious code in @aspect-adv-ui/consent-manager (npm)

MAL-2026-16050

Published · Modified

Dependency scanning

Check whether @aspect-adv-ui/consent-manager is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Description


__

Source: amazon-inspector (b30b507d6c71f746b0af2d19cbbb85357f15189e7e93118c75b4cb215adc0ece)

@aspect-adv-ui/consent-manager 2.4.1 declares a postinstall hook (node setup.js) that fires automatically on every npm install. setup.js issues an HTTPS GET to a hardcoded webhook.site inspection endpoint (https://webhook.site/kapper), sending install-event metadata (source IP, TLS/user-agent fingerprint) to an author-controlled third-party collector. The package is advertised as a small GDPR/CCPA consent-bar React component with no native build, no binary, and no legitimate install-time work; the postinstall exists solely to run this beacon. webhook.site is a public request-inspection service commonly used as an anonymous exfiltration/beacon endpoint, and the beacon is not disclosed or opt-in.

Ready to move

Start Securing

Free, no credit card | First findings in minutes