{"id":"MAL-2026-16116","summary":"Malicious code in etoro-builders (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (c9210fb131a2f661ae1d656fa461d45c6c54377179aecba06e6a07b4f357a00b)\nThe package's preinstall lifecycle script (preinstall.js) reads the installer's OS hostname, username, and current working directory via os.hostname(), os.userInfo().username, and process.cwd(), encodes them into a URL path, and issues an HTTP GET to a hardcoded bare-IP endpoint at http://209.126.81.147/etoro-depconf-.../npm/\u003chostname\u003e/\u003cusername\u003e/\u003ccwd\u003e. The package name 'etoro-builders' combined with the implausibly high version 999.0.0 and minimal placeholder contents is consistent with a dependency-confusion payload designed to win resolution against a private internal package and beacon successful installs to the operator. Installer host identifiers leave the machine at npm install time to a third-party bare-IP host over cleartext HTTP.\n","modified":"2026-09-10T05:30:11.597390692Z","published":"2026-09-10T04:45:48Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-09-10T05:18:06.198533992Z","modified_time":"2026-09-10T04:45:48Z","sha256":"c9210fb131a2f661ae1d656fa461d45c6c54377179aecba06e6a07b4f357a00b","source":"amazon-inspector","versions":["999.0.0"],"id":"IN-MAL-2026-019914"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/etoro-builders/v/999.0.0"}],"affected":[{"package":{"name":"etoro-builders","ecosystem":"npm","purl":"pkg:npm/etoro-builders"},"versions":["999.0.0"],"database_specific":{"indicators":{"package_integrity":[{"filename":"etoro-builders-999.0.0.tgz","hashes":{"sha1":"ef20e4d5f843ca74afa0f1ee87f1c7b8c1275db2","sha512_sri":"sha512-fXFmgIXCaY4OxVS+ts343kf0DcEpBl5RtBmaE7Bk+8ZxN0KiQoQrtt6pn7qbEJdlgx7BQ7lOCag7zkQRj7uwPA=="}}],"evidence_files":[{"tlsh":"ebe027f4118ca6683ccc01c4636b191ed4dfc705bcdec8c04a55d78587b15f1d6115f0","path":"preinstall.js","sha256":"bee47062733940943fd3a66654f0258135fd62911674304ccac11a43226b5f58"}]},"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/etoro-builders/MAL-2026-16116.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}