Vulnerability MAL-2026-17433

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
2 days ago
September 30, 2026 at 07:11 AM UTC
Malicious code in figma-to-apl (npm)
>=0.0.0
>=0.0.0

Summary

Malicious code in figma-to-apl (npm)

Details

figma-to-apl is a dependency-confusion package: it takes a name that looks like an internal project, uses an inflated version (100.0.0) so it outranks private-registry versions, and runs node setup.js || true as a preinstall script on npm install. setup.js sends the hostname, username, working directory, OS, architecture, Node.js version and configured npm registry, with a per-package tracking token, in an HTTPS POST to https://s85r5k14qk.execute-api.us-east-1.amazonaws.com/prod/hook. The npm account amel10 published figma-to-apl and 9 similar packages within two minutes on 2026-09-30, all with the same setup.js.

Impacted packages

Timeline

Published
2 days ago
September 30, 2026 at 07:11 AM UTC
Last Modified
2 hours ago
October 02, 2026 at 04:45 AM UTC