Logo
npm

alpha-helper@1.3.4

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 10:33 AM UTC

Malicious

OSV ID

MAL-2026-12338

Ecosystem

npm

Summary

The exported getPlugin in index.js issues an HTTPS request to a hardcoded bare-IP endpoint at 46.183.25.232:45000/icons/116 and passes the response field data.credits into a new Function(...) constructor with require, module, process, Buffer, and Promise bound into scope. Any consumer calling the exported function runs attacker-controlled JavaScript with full Node privileges. index.js also contains a decoy setDefaultModule that builds cdnjs-style font-awesome URLs across cloudflare/fastly/jsdelivr hostnames, which is not on the reachable code path. The package.json describes the module as a lightweight utility toolkit while the README describes an unrelated gamified trading system, and declared runtime dependencies include @primno/dpapi (Windows DPAPI unwrap), better-sqlite3, and node-machine-id, consistent with staging for browser-credential extraction.

Source: amazon-inspector (9758eecca0cf755a3c7cc43115b413dfda31f149bbeed40cdfaeb5e46d739efb)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.