OpenSSF/OSV advisory MAL-2026-3675 confirms this npm version as malicious. index.js executes on require as an IIFE that reassigns console.warn/error (and adds console.SL/FB/N) to forward arguments via fetch() to a hardcoded Telegram bot (989543891 with chat IDs -1001161709623/-1001433099398/-1001482347974), a hardcoded Slack webhook (T021S1VDCEB/B0221B6786T/UEUp2F6L4sOzKY5XcuI6WdZw), two Firebase RTDBs (iiilll.firebaseio.com, i----i.firebaseio.com), and imgbb...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in 6cc (npm)
Details
index.js executes on require as an IIFE that reassigns console.warn/error (and adds console.SL/FB/N) to forward arguments via fetch() to a hardcoded Telegram bot (989543891 with chat IDs -1001161709623/-1001433099398/-1001482347974), a hardcoded Slack webhook (T021S1VDCEB/B0221B6786T/UEUp2F6L4sOzKY5XcuI6WdZw), two Firebase RTDBs (iiilll.firebaseio.com, i----i.firebaseio.com), and imgbb. Any installer that requires this package has subsequent console output — which routinely contains stack traces, internal state, tokens, and PII — silently relayed out of process to attacker infrastructure. The 17,576-entry 3-letter alphabet array is used to generate opaque Firebase keys for the collection bucket, corroborating that this is maintained exfiltration infrastructure, not an accident. This is unambiguous installer-side harm with traced code evidence.
Decision reason
OpenSSF Malicious Packages via OSV confirms 6cc@0.2.8 as malicious (MAL-2026-3675): Malicious code in 6cc (npm)