@khaznatech/core @99.0.0
Vulnerability report · Last retrieved from osv.dev August 14, 2026 at 2:31 AM UTC
OSV ID
MAL-2026-13974
Ecosystem
npm
Summary
The package ships install-report.js as a preinstall lifecycle script that unconditionally runs on npm install. The script reads os.hostname() and the current working directory basename and transmits them via https.get to a hardcoded third-party collector at https://webhook.site/93b065ab-227f-4253-b940-361d00e9b870/, appending the host identifiers as the URL path. The destination is an anonymous request-inspection endpoint unrelated to any declared package purpose, and the beacon fires silently on every installation without opt-in.
Source: amazon-inspector (820c7f4f32895ef501e6926f624897cf41b5f868bc21c60852cbfc101b4cd5ba)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.