Malicious code in bender-rspack-config (npm)
MAL-2026-16221
Published · Modified
Dependency scanning
Check whether bender-rspack-config is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Description
__
Source: amazon-inspector (3a6997cea54ae81d1addcb41ddac29e94923dfa1042265253c555cb4945ad5b4)
package.json declares a preinstall lifecycle script that runs wget against a hardcoded webhook.site URL, embedding $(whoami), $(pwd), and $(hostname) as query-string parameters. The request fires automatically on npm install, transmitting the installer's username, working-directory path, and hostname to an author-controlled collector at webhook.site/9d385aa8-875e-48b6-938c-6c0f5a0e8319/. The behavior is self-labeled as a dependency-confusion proof of concept, but the shipped code is a functioning identity-beacon regardless of framing.
Source: ossf-package-analysis (159730c04aeb50c0e832685be81c3f332d8692bf4a9f1a419c7223dbe5059491)
The OpenSSF Package Analysis project identified 'bender-rspack-config' @ 1.0.0 (npm) as malicious.
It is considered malicious because:
- The package executes one or more commands associated with malicious behavior.
References
Ready to move
Start Securing
Free, no credit card | First findings in minutes