bazelisk @1.0.0
Vulnerability report · Last retrieved from osv.dev August 19, 2026 at 12:52 PM UTC
OSV ID
MAL-2026-14227
Ecosystem
npm
Summary
This npm package uses the name bazelisk , colliding with Google's bazelbuild/bazelisk project (referenced in the tarball's source.txt), and self-labels as a 'Security research canary'. Its postinstall script collects the installer's hostname, platform, arch, Node version, package name, and npm lifecycle event and POSTs that JSON payload to https://grqx3qve.instances.poc.jchunt.top/bazelisk at npm install time. The destination host is unrelated to the real bazelisk publisher. Installer host identifiers and environment fingerprint leave the machine automatically on install, matching a dependency-confusion beacon pattern.
Source: amazon-inspector (d4bcbd35130e716d1a2940c91b6691d41b9655fdc8587404af37bc6e5a7f1370)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.