🛡️ MAL-2026-6996 — ec-checker

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Malicious code in ec-checker (npm)

Source: amazon-inspector

package.json declares a preinstall script that runs npm install @sentry/node && node examples/verify.js. examples/verify.js initializes the package's Sentry client against a hardcoded author-owned DSN (https://bbdb73451ed2cd7e25e5529f78013624@o4510485815754752.ingest.us.sentry.io/4511621197856768) with sendDefaultPii enabled, calls setUserFromPublicIp() to resolve the installer's public IP, then deliberately throws a TypeError and flushes the Sentry event. As a result, simply running npm install ec-checker transmits the installer's public IP, hostname, OS, Node runtime info, and a stack trace to the author's Sentry project without the installer's consent. Separately, src/index.js hardcodes the same DSN as DEFAULT_DSN and falls back to it whenever a caller does not pass a dsn option or set SENTRY_DSN — and the README's quick-start invokes init() with no DSN — so consumers integrating the library per the documented usage silently upload their application's runtime exceptions (stack traces, file paths, user IPs, hostnames) to the author's Sentry tenant rather than their own. The install-time beacon gives the publisher an inventory of every machine that installs the package, and the library default turns the package into a silent relay of downstream application telemetry.

Affected software

MAL-2026-6996 is recorded against 1 package.

  • ec-checker

Timeline and source

Published on 8 July 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.npmjs.com (Package)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2026-07-08
Updated 2026-08-12
Modified 2026-07-08
Fix URL N/A

Affected Packages

Software From version Fixed in
ec-checker

Free Vulnerability Check

Is your site affected by MAL-2026-6996?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against MAL-2026-6996 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.