{"id":"MAL-2026-10208","summary":"Malicious code in @meziizana/frontend-logger (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (a7d77255cb713e19b9560cc339e937518fdbfb49ab048d9d5a65ad81c1309a9a)\npackage.json declares a preinstall lifecycle script that runs wget against https://webhook.site/f164a383-b9e7-4379-b18c-38bf41a3c152/ with query parameters carrying the installer's username ($(whoami)), current working directory ($(pwd)), and hostname ($(hostname)). This fires automatically on `npm install` with no user consent and sends installer-identifying reconnaissance data to a third-party collection endpoint. webhook.site is a public request-inspection service commonly abused as a low-effort exfiltration sink; the destination is not tied to any legitimate build or install task.\n","modified":"2026-07-12T21:31:53.495760806Z","published":"2026-07-12T20:49:38Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-009765","import_time":"2026-07-12T21:20:01.52792836Z","modified_time":"2026-07-12T20:49:38Z","sha256":"a7d77255cb713e19b9560cc339e937518fdbfb49ab048d9d5a65ad81c1309a9a","source":"amazon-inspector","versions":["10.0.0"]}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/@meziizana/frontend-logger/v/10.0.0"}],"affected":[{"package":{"name":"@meziizana/frontend-logger","ecosystem":"npm","purl":"pkg:npm/%40meziizana/frontend-logger"},"versions":["10.0.0"],"database_specific":{"indicators":{"evidence_files":[{"tlsh":"57f04cfb8628be53192687b025b1e24ef143f72f84765f2efcb72356106d8e02059b40","path":"package.json","sha256":"249cc0ba971b41a9a06232bf5672e394a8559d54d12de59ae33bbbfd3faf355c"}],"package_integrity":[{"hashes":{"sha1":"d6c196486ec3c854b6464e7dc65fd80f20bd008b","sha512_sri":"sha512-XmaqpVEs2GpegaBZEjLnPw7eGOhCLZNSZd592SHPiG9BdKwvpk4mxOGZmQ81P1ZZxq0t8ce7ML14Xw9lcrtX/g=="},"filename":"frontend-logger-10.0.0.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/@meziizana/frontend-logger/MAL-2026-10208.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.7.5","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}