{"id":"MAL-2026-16437","summary":"Malicious code in eslint-plugin-i18n-shreddit (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (3a22687900b0decfe83eda7516ec5c5169401894c98be27d115e5dffe64fc902)\neslint-plugin-i18n-shreddit@99.9.9 ships no ESLint plugin code; the tarball's only function is a postinstall hook (scripts.postinstall = 'node index.js') that runs automatically on `npm install`. index.js collects installer-side reconnaissance — os.userInfo().username, process.cwd(), os.hostname(), and the local IPv4 address — and POSTs the values as JSON to a hardcoded anonymous collector at https://webhook.site/f9bff304-3053-4d54-be05-86537267514a. Package metadata is characteristic of a dependency-confusion probe: version 99.9.9 (chosen to win resolution against a lower-versioned internal package of the same name), empty description, empty author, and no exported plugin functionality. Installing this package leaks the installer's identifiers and network position to an attacker-controlled webhook, identifying vulnerable internal build environments for follow-on targeting.\n","modified":"2026-09-23T02:00:06.984630495Z","published":"2026-09-23T01:36:44Z","database_specific":{"malicious-packages-origins":[{"modified_time":"2026-09-23T01:36:44Z","sha256":"3a22687900b0decfe83eda7516ec5c5169401894c98be27d115e5dffe64fc902","source":"amazon-inspector","versions":["99.9.9"],"id":"IN-MAL-2026-020323","import_time":"2026-09-23T01:50:18.862422556Z"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/eslint-plugin-i18n-shreddit/v/99.9.9"}],"affected":[{"package":{"name":"eslint-plugin-i18n-shreddit","ecosystem":"npm","purl":"pkg:npm/eslint-plugin-i18n-shreddit"},"versions":["99.9.9"],"database_specific":{"cwes":[{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"sha256":"c6896a08c348b263f3a12ffae3897427ad5630c47c19944543e54ae900aec932","tlsh":"0c01cee588ab10100fb177b14c024c05f7215722b51a9781b9bcc29d2f969a5a271eec","path":"index.js"},{"path":"package.json","sha256":"3296021daa6a7b2c9fd690349440dec739004dc08ed5aa6cae8919448276d682","tlsh":"63d0a7349c30962369d45a9a09676547b6a18f5f0058b80ca7e36428d3eea7344fe20e"}],"package_integrity":[{"hashes":{"sha1":"642131892fe99e8abf3ad48c92ff874514361c87","sha512_sri":"sha512-GAsImKzFtFYxMIWKGBQzYCM7Eu4Eoj+vPTHUEoAGRk8PJvCO3TJIUa2q0MG4KFen4I5KkSIw8vQbE2ly8Rm2ew=="},"filename":"eslint-plugin-i18n-shreddit-99.9.9.tgz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/eslint-plugin-i18n-shreddit/MAL-2026-16437.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}