Malicious code in moudeva (npm)
MAL-2026-16442
Published · Modified
Dependency scanning
Check whether moudeva is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Description
__
Source: amazon-inspector (dec843001e36153e09f56c056031d90bf3bcf909a5fe0469f8b27cbed7361c3a)
The package's main.js references child_process at multiple locations (lines 19, 883, 961) alongside HTTP POST calls (lines 365, 369) to a hardcoded endpoint https://ipc.shadxino.internal (referenced at lines 359 and 453). The.internal TLD is not a publicly registrable domain and is consistent with an attacker-controlled or otherwise non-legitimate destination that resolves only in a controlled network context. The co-location of a shell/process-execution primitive with an unconditional POST to a fixed non-standard host inside a single module matches the shape of installer-side command execution and data exfiltration.
References
Ready to move
Start Securing
Free, no credit card | First findings in minutes