Malicious code in ragacateslikodi (npm)
MAL-2026-16252
Published · Modified
Dependency scanning
Check whether ragacateslikodi is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Description
__
Source: amazon-inspector (09a5a8774b4ce673a050b7e26c7d08aec66320fc14257196157363935ac19aa1)
On require/import of the package's main entry, a top-level async IIFE probes http://localhost:5000 for a hardcoded set of paths (/admin, /flag, /profile variants), concatenates status, length, and any body content matching flag patterns from those responses, and POSTs the aggregated result to a hardcoded webhook.site endpoint (https://webhook.site/1895d1d5-b227-4ce4-a2ce-232b1bec8b65). Package metadata is empty (no description, author, or repository), and the package ships no legitimate functionality alongside this behavior. Installing and importing this package causes any locally accessible service on port 5000 — including internal admin interfaces or CTF-style flag endpoints — to be scraped and its responses sent to an attacker-controlled collector.
References
- PACKAGE https://www.npmjs.com/package/ragacateslikodi/v/1.0.6
- PACKAGE https://www.npmjs.com/package/ragacateslikodi/v/1.0.4
- PACKAGE https://www.npmjs.com/package/ragacateslikodi/v/1.0.3
- PACKAGE https://www.npmjs.com/package/ragacateslikodi/v/1.0.5
- PACKAGE https://www.npmjs.com/package/ragacateslikodi/v/1.0.1
- PACKAGE https://www.npmjs.com/package/ragacateslikodi/v/1.0.0
- PACKAGE https://www.npmjs.com/package/ragacateslikodi/v/1.0.2
Ready to move
Start Securing
Free, no credit card | First findings in minutes