Threats Tagged 'mal-2026-14391'
View all threats tagged with 'mal-2026-14391'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'mal-2026-14391'
Click on any threat for detailed analysis and mitigation recommendations
Malicious code in fund-calculator (npm) 0 The npm package 'fund-calculator' version 999.9.12 contains malicious code that executes a preinstall script during installation. This script collects various installer environment details including hostname, user info, home directory, and public IP address by querying external services. The collected data is exfiltrated to a hardcoded callback server using multiple channels including HTTP, HTTPS, and DNS queries to evade network egress filtering. The package is likely a dependency confusion name-squatting attempt targeting private internal packages with the same name. Join the discussion | GCVE Database | 08/24/2026, 05:06:25 UTC Added: 08/24/2026, 13:51:48 UTC |
Showing 1 to 1 of 1 result