CRITICAL npm Malware

Malicious code in bender-rspack-config (npm)

MAL-2026-16221

Published · Modified

Dependency scanning

Check whether bender-rspack-config is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Description


__

Source: amazon-inspector (3a6997cea54ae81d1addcb41ddac29e94923dfa1042265253c555cb4945ad5b4)

package.json declares a preinstall lifecycle script that runs wget against a hardcoded webhook.site URL, embedding $(whoami), $(pwd), and $(hostname) as query-string parameters. The request fires automatically on npm install, transmitting the installer's username, working-directory path, and hostname to an author-controlled collector at webhook.site/9d385aa8-875e-48b6-938c-6c0f5a0e8319/. The behavior is self-labeled as a dependency-confusion proof of concept, but the shipped code is a functioning identity-beacon regardless of framing.

Source: ossf-package-analysis (159730c04aeb50c0e832685be81c3f332d8692bf4a9f1a419c7223dbe5059491)

The OpenSSF Package Analysis project identified 'bender-rspack-config' @ 1.0.0 (npm) as malicious.

It is considered malicious because:

  • The package executes one or more commands associated with malicious behavior.

Ready to move

Start Securing

Free, no credit card | First findings in minutes