{"id":"MAL-2026-16218","summary":"Malicious code in tol8t (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (c33f4cd3c64d0ca0eb65dc5947fce3700c94ec8bea6083e63da1e6ba31321e27)\npackage.json declares preinstall and postinstall lifecycle hooks that use wget to POST installer host identifiers to a hardcoded Discord webhook at https://discord.com/api/webhooks/1413937656697720862/. The preinstall hook sends the installer's current working directory ($(pwd)) and the postinstall hook sends the machine hostname ($(hostname)). Both fire automatically during `npm install` with no user interaction. The package ships no other functionality; its sole behavior is host reconnaissance beaconing to an attacker-controlled Discord webhook.\n\n## Source: ossf-package-analysis (2f9850f64422a733207e07792098b0e3c72d43311f73a44bd07ae0c2dd4429eb)\nThe OpenSSF Package Analysis project identified 'tol8t' @ 14.0.0 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n\n- The package executes one or more commands associated with malicious behavior.\n","modified":"2026-09-16T10:30:09.553835614Z","published":"2026-09-15T20:05:48Z","database_specific":{"malicious-packages-origins":[{"id":"IN-MAL-2026-020084","import_time":"2026-09-16T06:56:08.696676448Z","modified_time":"2026-09-16T06:35:20Z","sha256":"c33f4cd3c64d0ca0eb65dc5947fce3700c94ec8bea6083e63da1e6ba31321e27","source":"amazon-inspector","versions":["14.0.0"]},{"versions":["14.0.0"],"import_time":"2026-09-16T10:19:31.278636485Z","modified_time":"2026-09-15T20:05:48Z","sha256":"2f9850f64422a733207e07792098b0e3c72d43311f73a44bd07ae0c2dd4429eb","source":"ossf-package-analysis"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/tol8t/v/14.0.0"}],"affected":[{"package":{"name":"tol8t","ecosystem":"npm","purl":"pkg:npm/tol8t"},"versions":["14.0.0"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"indicators":{"package_integrity":[{"filename":"tol8t-14.0.0.tgz","hashes":{"sha1":"f24080f43309bd1b57d293a65584801b46453f8f","sha512_sri":"sha512-LzdFYiStEIDAcA0FUj3kDnsrQ52qaKh79OY+R83GoG7GA+5tvmVFKgIk4w5AhlZuZ4O0CqJhCkqX05Hwu+zZsQ=="}}],"evidence_files":[{"path":"package.json","sha256":"69c60f355331f8f0f6364e12af72204e6453d8874ef236065d33e09aec4fac55","tlsh":"4e01d0f19e217632bbd795f71a2756586fe3685f1804582ca19346ac21cc367203668b"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/tol8t/MAL-2026-16218.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"OpenSSF: Package Analysis","contact":["https://github.com/ossf/package-analysis","https://openssf.slack.com/channels/package_analysis"],"type":"FINDER"}]}