ai-workshop-radio-app@100.0.0
Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC
OSV ID
MAL-2026-17428
Ecosystem
npm
Summary
The package declares a preinstall hook that runs setup.js on npm install. setup.js collects the installer's hostname, OS username, current working directory, platform, architecture, Node version, and the configured npm registry URL, and POSTs them as JSON to the hardcoded endpoint https://s85r5k14qk.execute-api.us-east-1.amazonaws.com/prod/hook together with a static per-package token identifier. The advertised purpose is a trivial date-format helper, which has no functional need for install-time host telemetry to a third-party endpoint. The npm_config_registry field can additionally leak internal or private registry hostnames belonging to the installer's organization.
Source: amazon-inspector (80be82f81013b8be89b5650c3a196776faeece26b7f24346bf2f531179b0e2a0)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.