Skip to content

Malicious code in zeal-rq-hooks (npm)

Malware Published Aug 11, 2026 to the GitHub Advisory Database

Package

npm zeal-rq-hooks (npm)

Affected versions

= 0.0.0

Patched versions

None

Description

Source: amazon-inspector (dcf7e926ec85f72f362263a19d4f99c4b215ddd94ed4454c669c3387cacee164)

The package includes canary.js which imports os/http/https and, at line 123, POSTs a JSON body containing os.hostname(), os.userInfo(), process.platform, node/npm version, and cwd to the hardcoded endpoint https://npm-canary.aveliscare.com. The hostname is not associated with the npm registry or a documented publisher and is embedded directly in the package's own shipped code. The collected fields (hostname, username, platform, cwd) are host-identifying reconnaissance data, and the network destination is not user-configurable in the flagged code path.


Credit: OpenSSF (source)

References

Published to the GitHub Advisory Database Aug 11, 2026
Reviewed Aug 11, 2026

EPSS score

Weaknesses

Embedded Malicious Code

The product contains code that appears to be malicious in nature. Learn more on MITRE.

GHSA ID

GHSA-62m8-8rfw-gv5v

Source code

No known source code
Improvements are not currently accepted on this advisory because this package is malware and has no patched versions. If there is something to change, please open an issue at https://github.com/github/advisory-database/issues.