{"id":"MAL-2026-17430","summary":"Malicious code in alexa-cybertron-team-code-review-agent (npm)","details":"alexa-cybertron-team-code-review-agent is a dependency-confusion package: it takes a name that looks like an internal project, uses an inflated version (100.0.0) so it outranks private-registry versions, and runs `node setup.js || true` as a preinstall script on npm install. setup.js sends the hostname, username, working directory, OS, architecture, Node.js version and configured npm registry, with a per-package tracking token, in an HTTPS POST to `https://s85r5k14qk.execute-api.us-east-1.amazonaws.com/prod/hook`. The npm account amel10 published alexa-cybertron-team-code-review-agent and 9 similar packages within two minutes on 2026-09-30, all with the same setup.js.","modified":"2026-10-02T04:45:14.249893939Z","published":"2026-09-30T07:11:21Z","database_specific":{"iocs":{"files":[{"paths":["package.json"],"source":"PACKAGE_ARCHIVE","digests":{"sha256":"c5f28ae1a2dde60a5ac8c42066f930ec0c5e1f9533e0999a66330230d68f300c"},"note":"preinstall: node setup.js || true"},{"digests":{"sha256":"a8d5442cc56f67926957874f1ec279811fb797dcf0142a6fd3de47bd6f0ab98d"},"note":"Executed by the preinstall script.","paths":["setup.js"],"source":"PACKAGE_ARCHIVE"}],"urls":["https://s85r5k14qk.execute-api.us-east-1.amazonaws.com/prod/hook"],"domains":["s85r5k14qk.execute-api.us-east-1.amazonaws.com"]}},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/alexa-cybertron-team-code-review-agent"}],"affected":[{"package":{"name":"alexa-cybertron-team-code-review-agent","ecosystem":"npm","purl":"pkg:npm/alexa-cybertron-team-code-review-agent"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}],"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/alexa-cybertron-team-code-review-agent/MAL-2026-17430.json"}}],"schema_version":"1.9.0","credits":[{"name":"InvisiRisk, Inc.","contact":["https://www.invisirisk.com","mailto:research@invisirisk.com"],"type":"FINDER"}]}