MAL-2026-17430

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/alexa-cybertron-team-code-review-agent/MAL-2026-17430.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17430
Published
2026-09-30T07:11:21Z
Modified
2026-10-02T04:45:14Z
Summary
Malicious code in alexa-cybertron-team-code-review-agent (npm)
Details

alexa-cybertron-team-code-review-agent is a dependency-confusion package: it takes a name that looks like an internal project, uses an inflated version (100.0.0) so it outranks private-registry versions, and runs node setup.js || true as a preinstall script on npm install. setup.js sends the hostname, username, working directory, OS, architecture, Node.js version and configured npm registry, with a per-package tracking token, in an HTTPS POST to https://s85r5k14qk.execute-api.us-east-1.amazonaws.com/prod/hook. The npm account amel10 published alexa-cybertron-team-code-review-agent and 9 similar packages within two minutes on 2026-09-30, all with the same setup.js.

Database specific
{
    "iocs":  {
        "domains":  [
            "s85r5k14qk.execute-api.us-east-1.amazonaws.com"
        ],
        "files":  [
            {
                "digests":  {
                    "sha256":  "c5f28ae1a2dde60a5ac8c42066f930ec0c5e1f9533e0999a66330230d68f300c"
                },
                "note":  "preinstall: node setup.js || true",
                "paths":  [
                    "package.json"
                ],
                "source":  "PACKAGE_ARCHIVE"
            },
            {
                "digests":  {
                    "sha256":  "a8d5442cc56f67926957874f1ec279811fb797dcf0142a6fd3de47bd6f0ab98d"
                },
                "note":  "Executed by the preinstall script.",
                "paths":  [
                    "setup.js"
                ],
                "source":  "PACKAGE_ARCHIVE"
            }
        ],
        "urls":  [
            "https://s85r5k14qk.execute-api.us-east-1.amazonaws.com/prod/hook"
        ]
    }
}
References
Credits

Affected packages

npm / alexa-cybertron-team-code-review-agent

Package

Name
alexa-cybertron-team-code-review-agent
View open source insights on deps.dev
Purl
pkg:npm/alexa-cybertron-team-code-review-agent

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Database specific

cwes
[
    {
        "cweId":  "CWE-506",
        "description":  "The product contains code that appears to be malicious in nature.",
        "name":  "Embedded Malicious Code"
    }
]
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/alexa-cybertron-team-code-review-agent/MAL-2026-17430.json"