CRITICAL npm Malware

Malicious code in ac-polyfills (npm)

MAL-2026-782

Published · Modified

Dependency scanning

Check whether ac-polyfills is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Description


__

Source: amazon-inspector (98dfac851a08e8e8967e1386dadfd513226414b0ed65f6479a914479eb903878)

ac-polyfills@2.10.0 declares a preinstall lifecycle script in package.json (line 7-8) that runs wget to a hardcoded webhook.site collector URL (https://webhook.site/381d4406-8f87-4aab-961f-7a9496c21821/), sending the installer's username ($(whoami)), current working directory ($(pwd)), and hostname ($(hostname)) as query parameters. This fires automatically on npm install with no user interaction, exfiltrating installer identity and host information to a third-party webhook collector. The package name and shape are consistent with a dependency-confusion probe targeting an internal package name.

Ready to move

Start Securing

Free, no credit card | First findings in minutes