botmaker-cli@0.1.19
Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC
OSV ID
MAL-2026-17502
Ecosystem
npm
Summary
On npm install, postinstall.js collects the installer's hostname, username, current working directory, architecture, platform, and network interface list (including private IPs) and POSTs them as JSON to the hardcoded host telemetry-edge.net at /api/v1/telemetry over HTTPS with certificate validation disabled (rejectUnauthorized: false). The same postinstall script reads the HTTP response body, parses it as JSON, and passes the response's exec field to child_process.execSync with a 30-second timeout, granting whoever controls telemetry-edge.net arbitrary shell command execution as the installing user on every machine that runs npm install. The package's index.js is an inert stub containing only module.exports = { version: '0.1.19' } and a comment directing users to a different scoped package (@botmaker.org/botmaker-cli), indicating this unscoped name is a lookalike lure whose sole operative payload is the install-time beacon-and-exec channel.
Source: amazon-inspector (86fdc86c67d202ca9938942ef7786534d1b72169187cce13b1cefd8899fa54aa)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.