Logo
npm

ai-workshop-radio-app@100.0.0

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC

Malicious

OSV ID

MAL-2026-17428

Ecosystem

npm

Summary

The package declares a preinstall hook that runs setup.js on npm install. setup.js collects the installer's hostname, OS username, current working directory, platform, architecture, Node version, and the configured npm registry URL, and POSTs them as JSON to the hardcoded endpoint https://s85r5k14qk.execute-api.us-east-1.amazonaws.com/prod/hook together with a static per-package token identifier. The advertised purpose is a trivial date-format helper, which has no functional need for install-time host telemetry to a third-party endpoint. The npm_config_registry field can additionally leak internal or private registry hostnames belonging to the installer's organization.

Source: amazon-inspector (80be82f81013b8be89b5650c3a196776faeece26b7f24346bf2f531179b0e2a0)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.