a-onesite@99.9.9
Vulnerability report · Last retrieved from osv.dev September 23, 2026 at 10:54 PM UTC
OSV ID
MAL-2026-16480
Ecosystem
npm
Summary
a-onesite@99.9.9 ships an empty index.js and no library functionality. Its package.json declares preinstall, preupdate, and test scripts that all invoke wget against http://eoy34oyrep9j5x8.m.pipedream.net with the installer's username ($(whoami)), current working directory ($(pwd)), and hostname ($(hostname)) as query parameters. The preinstall hook fires automatically on npm install, sending installer-identifying reconnaissance data over plaintext HTTP to a third-party collection endpoint unrelated to any advertised purpose. The version number (99.9.9) and empty code payload are consistent with a dependency-confusion reconnaissance beacon rather than a functional package.
Source: amazon-inspector (1b1ed6ca931448c083b5356eae6ad5af3cce9011d70fce4ce4ad427349991856)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.