Logo
npm

ai-workshop-radio-lambda@100.0.0

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC

Malicious

OSV ID

MAL-2026-17429

Ecosystem

npm

Summary

The package declares a preinstall lifecycle script (node setup.js) that runs automatically on npm install. setup.js collects installer-identifying data — os.hostname(), os.userInfo().username, process.cwd(), process.platform, process.arch, Node version, and the configured npm registry — and POSTs it together with a hardcoded static token to https://s85r5k14qk.execute-api.us-east-1.amazonaws.com/prod/hook. The package's advertised functionality is a trivial add-two-numbers utility that has no legitimate need for host reconnaissance or outbound network activity at install time. The package name (ai-workshop-radio-lambda) and implausibly high version (100.0.0) are consistent with a dependency-confusion lure designed to win resolution against an internal package of the same name.

Source: amazon-inspector (c626f28127d1b54e624e5dc670ae6a87aadcc7776de72d3597a16e9c0fa2b48f)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.