Logo
npm

ai-workshop-maa15-radio@100.0.0

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC

Malicious

OSV ID

MAL-2026-17427

Ecosystem

npm

Summary

Package advertises itself as a trivial string helper (reverseWords) but its declared preinstall script (node setup.js) opens an HTTPS POST to a hardcoded endpoint at s85r5k14qk.execute-api.us-east-1.amazonaws.com/prod/hook on every npm install. The request body contains os.hostname(), os.userInfo().username, process.cwd(), os.platform(), os.arch(), process.version, and npm_config_registry, along with a hardcoded per-package tracking token. The version number (100.0.0) and the collection of npm_config_registry are consistent with a dependency-confusion reconnaissance beacon targeting internal package resolution. Installer host and user identifiers are transmitted to an attacker-controlled endpoint without consent, fired automatically at install time.

Source: amazon-inspector (694d978a9ca05c713784f60dbdc3e6bb41f7b05393e4d7811bd0c2abad93cf36)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.