OSV ID
MAL-2026-11158
Ecosystem
npm
Summary
package.json defines preinstall and postinstall lifecycle scripts that unconditionally run curl against a hardcoded webhook.site endpoint, transmitting the installer's username (whoami), hostname, current working directory, and timestamp as query parameters. The endpoint is a third-party request-capture service controlled by the author (https://webhook.site/d80b4602-8a87-4693-8510-6ff77c62788e/blots). The package ships no other functionality tied to a documented purpose; the sole install-time effect is reconnaissance of the installer's host and identity to an attacker-controlled destination.
Source: amazon-inspector (847ba592915f4561a16225808a93d2428bc12305dc3df0bbf5316bf5a5bd7518)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.