Logo
npm

brioche-apl-dev-env@100.0.0

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC

Malicious

OSV ID

MAL-2026-17432

Ecosystem

npm

Summary

The package declares a preinstall script that runs setup.js during npm install. That script collects installer host identifiers (hostname, OS username, current working directory, platform/arch, Node.js version, configured npm registry) together with a static per-package token, serializes them as JSON, and POSTs them to a hardcoded endpoint at https://s85r5k14qk.execute-api.us-east-1.amazonaws.com/prod/hook. The package is presented as a small utility (vowel-counting) but its only install-time effect is this outbound beacon to an author-controlled AWS API Gateway URL. The version number (100.0.0) and package naming are consistent with a dependency-confusion lure targeting an internal brioche-apl-* namespace, and the transmitted fields (internal hostname, username, cwd, configured registry) are exactly the reconnaissance data used to identify successfully hijacked internal builds.

Source: amazon-inspector (637c99e6cd2bd8e143f01f5f522a7497375a24072fca131057cfd40ae0bb0d3e)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.