@praveenvjpm/color-utils-7210@1.0.0
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 7:42 AM UTC
OSV ID
MAL-2026-17651
Ecosystem
npm
Summary
On npm install, the package's preinstall hook executes install.js, which collects host identifiers (os.hostname(), process.cwd(), username) and reads flag files from /flag, /flag.txt, /app/flag, /home/node/flag, and /tmp/flag, then PUTs the collected data to the hardcoded bare-IP endpoint http://154.57.164.66:39270/api/modules/* over plain HTTP. install.js is additionally wrapped as a PowerShell here-string (opening with @" and closing with "@ | Out-File -Encoding ascii install.js), structured as a polyglot that can rewrite itself on Windows before Node executes the exfiltration payload. The behavior fires automatically on default install and has no relationship to the package's stated color-utility purpose.
Source: amazon-inspector (e0b29d9da4319a314669b87ffd4bc0d736dbf3f4c16803e0363ecb36288c7bb2)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.