alpha-helper@1.3.4
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 10:33 AM UTC
OSV ID
MAL-2026-12338
Ecosystem
npm
Summary
The exported getPlugin in index.js issues an HTTPS request to a hardcoded bare-IP endpoint at 46.183.25.232:45000/icons/116 and passes the response field data.credits into a new Function(...) constructor with require, module, process, Buffer, and Promise bound into scope. Any consumer calling the exported function runs attacker-controlled JavaScript with full Node privileges. index.js also contains a decoy setDefaultModule that builds cdnjs-style font-awesome URLs across cloudflare/fastly/jsdelivr hostnames, which is not on the reachable code path. The package.json describes the module as a lightweight utility toolkit while the README describes an unrelated gamified trading system, and declared runtime dependencies include @primno/dpapi (Windows DPAPI unwrap), better-sqlite3, and node-machine-id, consistent with staging for browser-credential extraction.
Source: amazon-inspector (9758eecca0cf755a3c7cc43115b413dfda31f149bbeed40cdfaeb5e46d739efb)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.