{"id":"MAL-2026-15922","summary":"Malicious code in claude-channel-discord (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (40db25d41cbf34007ee5be9e31462d8346c3ec51dcb5b72160e76739aaedf4ad)\nclaude-channel-discord@9.9.9 is a dependency-confusion probe. package.json declares preinstall and postinstall hooks (`node index.js --save-prod`) and a main entry that both execute index.js, which reads os.hostname() and issues a GET to https://eo8f3m3ho26a0nm.m.pipedream.net/claude-channel-discord?h=${hostname}. The beacon fires automatically on `npm install` and again on `require()` of the package. The package has an empty description, an implausibly high 9.9.9 version, a self-referential dependency, and a name shaped to collide with an internal or typoed identifier — the canonical dependency-confusion reconnaissance pattern, leaking the installer's host identifier to an author-controlled Pipedream collection endpoint.\n","modified":"2026-09-04T07:00:08.818129832Z","published":"2026-09-04T06:37:18Z","database_specific":{"malicious-packages-origins":[{"versions":["9.9.9"],"id":"IN-MAL-2026-019637","import_time":"2026-09-04T06:53:31.646549087Z","modified_time":"2026-09-04T06:37:18Z","sha256":"40db25d41cbf34007ee5be9e31462d8346c3ec51dcb5b72160e76739aaedf4ad","source":"amazon-inspector"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/claude-channel-discord/v/9.9.9"}],"affected":[{"package":{"name":"claude-channel-discord","ecosystem":"npm","purl":"pkg:npm/claude-channel-discord"},"versions":["9.9.9"],"database_specific":{"indicators":{"package_integrity":[{"hashes":{"sha512_sri":"sha512-EBFUHt7Wa32nmooZCXFQj0lxX5uyzMHHF33CA5qLOOMnQk75hUJjiloQwwvhzLCp1TMs6vEsn4elMmpvo09e7Q==","sha1":"e4615c949099b4c4b6f7e42293d87d1b4a2df090"},"filename":"claude-channel-discord-9.9.9.tgz"}],"evidence_files":[{"sha256":"0ea71ec4d2869fc3ef7f5c8ee2f86eb47d3d5f5bc47c3631b74cb920e9d1dde5","tlsh":"94d0a7c30be8732465c0998082925a077317e10671b88174905d46d99dd64e00923ce0","path":"index.js"},{"path":"package.json","sha256":"1a8a0104d65ef9dba336cd153ffcc2e92abec4fac986f31277141f513591e28e","tlsh":"f9f0a792cc505b7310f822e856b61a07b2511f1b515c4d0b34f7a48c96a2163449af2a"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/claude-channel-discord/MAL-2026-15922.json","cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}]}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}