Malicious code in ac-polyfills (npm)
MAL-2026-782
Published · Modified
Dependency scanning
Check whether ac-polyfills is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Description
__
Source: amazon-inspector (98dfac851a08e8e8967e1386dadfd513226414b0ed65f6479a914479eb903878)
ac-polyfills@2.10.0 declares a preinstall lifecycle script in package.json (line 7-8) that runs wget to a hardcoded webhook.site collector URL (https://webhook.site/381d4406-8f87-4aab-961f-7a9496c21821/), sending the installer's username ($(whoami)), current working directory ($(pwd)), and hostname ($(hostname)) as query parameters. This fires automatically on npm install with no user interaction, exfiltrating installer identity and host information to a third-party webhook collector. The package name and shape are consistent with a dependency-confusion probe targeting an internal package name.
References
Ready to move
Start Securing
Free, no credit card | First findings in minutes