alexa-cybertron-team-code-review-agent is a dependency-confusion package: it takes a name that looks like an internal project, uses an inflated version (100.0.0) so it outranks private-registry versions, and runs node setup.js || true as a preinstall script on npm install. setup.js sends the hostname, username, working directory, OS, architecture, Node.js version and configured npm registry, with a per-package tracking token, in an HTTPS POST to https://s85r5k14qk.execute-api.us-east-1.amazonaws.com/prod/hook. The npm account amel10 published alexa-cybertron-team-code-review-agent and 9 similar packages within two minutes on 2026-09-30, all with the same setup.js.
{
"iocs": {
"domains": [
"s85r5k14qk.execute-api.us-east-1.amazonaws.com"
],
"files": [
{
"digests": {
"sha256": "c5f28ae1a2dde60a5ac8c42066f930ec0c5e1f9533e0999a66330230d68f300c"
},
"note": "preinstall: node setup.js || true",
"paths": [
"package.json"
],
"source": "PACKAGE_ARCHIVE"
},
{
"digests": {
"sha256": "a8d5442cc56f67926957874f1ec279811fb797dcf0142a6fd3de47bd6f0ab98d"
},
"note": "Executed by the preinstall script.",
"paths": [
"setup.js"
],
"source": "PACKAGE_ARCHIVE"
}
],
"urls": [
"https://s85r5k14qk.execute-api.us-east-1.amazonaws.com/prod/hook"
]
}
}[
{
"cweId": "CWE-506",
"description": "The product contains code that appears to be malicious in nature.",
"name": "Embedded Malicious Code"
}
]
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/alexa-cybertron-team-code-review-agent/MAL-2026-17430.json"