Vulnerability MAL-2026-17434
Summary
Malicious code in live-detection-dashboard (npm)
Details
live-detection-dashboard is a dependency-confusion package: it takes a name that looks like an internal project, uses an inflated version (100.0.0) so it outranks private-registry versions, and runs node setup.js || true as a preinstall script on npm install. setup.js sends the hostname, username, working directory, OS, architecture, Node.js version and configured npm registry, with a per-package tracking token, in an HTTPS POST to https://s85r5k14qk.execute-api.us-east-1.amazonaws.com/prod/hook. The npm account amel10 published live-detection-dashboard and 9 similar packages within two minutes on 2026-09-30, all with the same setup.js.