Malicious code in efhthrthrthregerht (npm)
MAL-2026-16436
Published · Modified
Dependency scanning
Check whether efhthrthrthregerht is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Description
__
Source: amazon-inspector (4845639223c486cf2d33751ad950cea4c7f70401877929d25c36e7d07655d820)
The package's postinstall hook runs index.js, which collects the installer's OS username, current working directory, hostname, and local IPv4 address and POSTs them as JSON to a hardcoded webhook.site collector URL (https://webhook.site/f9bff304-3053-4d54-be05-86537267514a) on npm install. The package name is a random keyboard-mash string with no documented purpose, and the only on-install behavior is the outbound beacon to an anonymous ephemeral webhook endpoint controlled by whoever created the webhook.site token.
References
Ready to move
Start Securing
Free, no credit card | First findings in minutes