Logo
npm

@aspect-adv-ui/consent-manager@2.4.1

Vulnerability report · Last retrieved from osv.dev September 9, 2026 at 12:08 AM UTC

Malicious

OSV ID

MAL-2026-16050

Ecosystem

npm

Summary

@aspect-adv-ui/consent-manager 2.4.1 declares a postinstall hook (node setup.js) that fires automatically on every npm install. setup.js issues an HTTPS GET to a hardcoded webhook.site inspection endpoint (https://webhook.site/kapper), sending install-event metadata (source IP, TLS/user-agent fingerprint) to an author-controlled third-party collector. The package is advertised as a small GDPR/CCPA consent-bar React component with no native build, no binary, and no legitimate install-time work; the postinstall exists solely to run this beacon. webhook.site is a public request-inspection service commonly used as an anonymous exfiltration/beacon endpoint, and the beacon is not disclosed or opt-in.

Source: amazon-inspector (b30b507d6c71f746b0af2d19cbbb85357f15189e7e93118c75b4cb215adc0ece)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.