@mohamed_nowisar/depconf-canary-test @0.0.1
Vulnerability report · Last retrieved from osv.dev August 19, 2026 at 3:49 AM UTC
OSV ID
MAL-2026-14134
Ecosystem
npm
Summary
On npm install , the package's preinstall hook runs node beacon.js , which collects host identity (os.hostname(), os.userInfo().username, process.cwd(), platform, arch, Node version) and CI-detection environment variables (GITLAB_CI, GITHUB_ACTIONS, YANDEX_CI, and others) and POSTs them as JSON to the hardcoded endpoint https://webhook.site/3687e44a-4e97-43c4-84c9-e6c93d4b2fbc. The package name and self-description frame this as a dependency-confusion canary, but the beacon fires automatically on install without opt-in and sends installer-side data to an author-controlled webhook.site collector.
Source: amazon-inspector (078a8dc3351eb44ee9ff0d5992b9082b726d7fbce0152ae2d44595a9e279ef82)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.