CRITICAL npm Malware

Malicious code in efhthrthrthregerht (npm)

MAL-2026-16436

Published · Modified

Dependency scanning

Check whether efhthrthrthregerht is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Description


__

Source: amazon-inspector (4845639223c486cf2d33751ad950cea4c7f70401877929d25c36e7d07655d820)

The package's postinstall hook runs index.js, which collects the installer's OS username, current working directory, hostname, and local IPv4 address and POSTs them as JSON to a hardcoded webhook.site collector URL (https://webhook.site/f9bff304-3053-4d54-be05-86537267514a) on npm install. The package name is a random keyboard-mash string with no documented purpose, and the only on-install behavior is the outbound beacon to an anonymous ephemeral webhook endpoint controlled by whoever created the webhook.site token.

Ready to move

Start Securing

Free, no credit card | First findings in minutes