npm

blots @2.1.1

Vulnerability report · Last retrieved from osv.dev August 5, 2026 at 5:03 PM UTC

Malicious

OSV ID

MAL-2026-11158

Ecosystem

npm

Summary

package.json defines preinstall and postinstall lifecycle scripts that unconditionally run curl against a hardcoded webhook.site endpoint, transmitting the installer's username (whoami), hostname, current working directory, and timestamp as query parameters. The endpoint is a third-party request-capture service controlled by the author (https://webhook.site/d80b4602-8a87-4693-8510-6ff77c62788e/blots). The package ships no other functionality tied to a documented purpose; the sole install-time effect is reconnaissance of the installer's host and identity to an attacker-controlled destination.

Source: amazon-inspector (847ba592915f4561a16225808a93d2428bc12305dc3df0bbf5316bf5a5bd7518)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.