@woodpecker-web-shared/components@2.20.5
Vulnerability report · Last retrieved from osv.dev September 21, 2026 at 11:45 PM UTC
OSV ID
MAL-2026-16354
Ecosystem
npm
Summary
On npm install, the package's postinstall hook runs node index.js, which collects installer host identifiers (os.hostname(), os.userInfo().username, os.platform(), architecture, cwd, node version, npm_lifecycle_event) and POSTs them as JSON to a hardcoded third-party collector at https://webhook.site/d9bc4bcc-ce74-4193-ae4e-96d234bb2220. The payload includes a src: 'loMesb' tag consistent with a campaign identifier used to correlate exfiltrated data across victims. The @woodpecker-web-shared/components scope/name has no legitimate reason to transmit installer identity to an anonymous webhook collector at install time, and the behavior fires automatically without user interaction. This is a recon beacon consistent with a dependency-confusion or typosquat lure.
Source: amazon-inspector (5f5f21bcc5464689c5b7c70819eeca4ea481f76b5f7dac0358cfe2d967da235f)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.