@ziedzzz/demo-canary@1.0.0
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 7:42 AM UTC
OSV ID
MAL-2026-17652
Ecosystem
npm
Summary
On npm install, the package's declared postinstall script executes index.js, which collects a host fingerprint (hostname, username, home directory, cwd, platform/arch/OS release, CPU model, memory, network interfaces including MAC/OUI, process info) and enumerates process.env for variable names matching TOKEN|SECRET|KEY|PASS|AWS_|GCP_|AZURE_|SSH|GIT|NPM|DOCKER. The collected data is transmitted via HTTPS GET to the hardcoded third-party endpoint telegrambot-aebk.onrender.com/ping. The behavior fires automatically on install without opt-in and discloses the installer's host identity and credential-variable inventory to an author-controlled destination.
Source: amazon-inspector (e6350184f3eabc17d37726cdd71ea97666cef28b2e1c125cffeb56e7c474b8dd)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.