localize-extractnpm
Advisory published Updated
localize-extract is a confirmed malicious npm package (MAL-2026-14249) that typosquats a legitimate package to trick installs (malicious version 1.0.0). Do not install it — remove it immediately and rotate any exposed credentials.
Malicious code in localize-extract (npm)
What this malware does
[email protected] executes a postinstall script that collects host identifiers (os.hostname(), platform, arch, node version, package name, lifecycle event) and POSTs them as JSON to the hardcoded endpoint https://1zrgq9h2.instances.poc.jchunt.top/localize-extract at npm install time. The package name resembles @angular/localize and the tarball references the upstream angular/localize package.json, consistent with a dependency-confusion / typosquat probe. Data leaves the installer's machine to an attacker-chosen host without consent on install.
Malicious versions
Indicators of compromise (SHA-256)
Detection & response playbook
TyposquatFind it
Search your lockfiles and build artifacts for localize-extract (version 1.0.0).
If you installed it — respond
localize-extract is a typosquat — you almost certainly intended a legitimately-named package. Remove localize-extract, install the correct package, and rotate any secrets exposed during the install since post-install scripts may have already run.
Did it already run?
If localize-extract was installed, its post-install payload may already have run. Removing the package does not undo that — check outbound connections and credential use from the install window onward.
Frequently asked questions
Campaign
References
Credits
- Amazon Inspector · finder
Detect & block this
O3 blocks localize-extract-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.