🛡️ MAL-2026-10957 — iphouse
Description
Malicious code in iphouse (npm)
The iphouse package was published to the npm registry by user 'jonothhu' (maintainer email [email protected]) as one of 19 packages in a dependency-confusion campaign targeting the 'markscan', 'akrai', and 'iphouse' namespaces, published in both unscoped and scoped (@scope/name) forms so that a misconfigured resolver installs the public lookalike instead of an intended private/internal dependency. Each package self-describes as an 'AUTHORIZED SECURITY RESEARCH CANARY' (static token PATHC-CANARY-2026, contact [email protected]), but ships an unconsented install-time beacon and provides no legitimate functionality.
The package declares a postinstall hook ("node postinstall.js") that executes automatically on npm install. The bundled postinstall.js collects host reconnaissance - the package/canary name, the static token 'PATHC-CANARY-2026', an event label, a UTC timestamp, the Node.js version, the current working directory, the platform, and os.hostname() - and exfiltrates it via HTTPS POST to a hardcoded anonymous dead-drop at https://webhook.site/129cb2ee-ba08-4b3c-989c-270dc0030350 (the same collector across all 19 packages). Request errors are swallowed.
The self-attestation of 'authorized security research' present in the package metadata is unverifiable and does not change the disposition: the package performs unconsented telemetry collection and exfiltration at install time to an anonymous collector, matching the behavior of a dependency-confusion reconnaissance beacon. Install-time behavior and the shared collector endpoint were confirmed by static analysis of a sample spanning all three namespaces and both scoped and unscoped variants.
Source: amazon-inspector
[email protected] ships a postinstall.js lifecycle script that runs unconditionally on npm install. It collects installer host identifiers (hostname, platform, current working directory, node version, timestamp) and POSTs them as JSON to a hardcoded webhook.site endpoint (https://webhook.site/129cb2ee-ba08-4b3c-989c-270dc0030350) controlled by the package author. There is no opt-in, no disclosure to the installer, and no legitimate package functionality accompanying the beacon — the package's only behavior is host-metadata exfiltration to an anonymous author-controlled endpoint.
Affected software
MAL-2026-10957 is recorded against 1 package.
- iphouse
Timeline and source
Published on 20 July 2026 and last revised on 4 August 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| iphouse | — | — |
References
Similar Threats
- Unknown MAL-2026-10958
- Unknown MAL-2026-10959
More MAL 2026 advisories
Browse all of MAL 2026 in the advisory index.
Free Vulnerability Check
Is your site affected by MAL-2026-10957?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against MAL-2026-10957 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.