alexa-cybertron-team-code-review-agent@100.0.0
Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC
OSV ID
MAL-2026-17430
Ecosystem
npm
Summary
npm package alexa-cybertron-team-code-review-agent@100.0.0 presents itself as a one-line titleCase utility (index.js is an inert stub) but declares a preinstall lifecycle hook node setup.js that runs automatically on npm install. setup.js collects installer host and user identifiers - os.hostname(), os.userInfo().username, process.cwd(), process.platform, process.arch, node version, and the configured npm registry - together with a hardcoded token, and POSTs them via https.request to the hardcoded endpoint https://s85r5k14qk.execute-api.us-east-1.amazonaws.com/prod/hook. The package name namespaces an internal-sounding team (alexa-cybertron-team-...) and is published at version 100.0.0, a shape consistent with a dependency-confusion probe designed to win resolution against a private internal package and report back which victim environments installed it. There is no relationship between the advertised titleCase functionality and the install-time host reconnaissance beacon.
Source: amazon-inspector (528ef9e111300abbee80027c6f51261639e05e482a6723919c9dba0f5e317c2c)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.