npm

chromeos-webdriver-cli @1.0.0

Vulnerability report · Last retrieved from osv.dev August 19, 2026 at 11:52 AM UTC

Malicious

OSV ID

MAL-2026-14232

Ecosystem

npm

Summary

The package's postinstall script runs on npm install and issues an HTTPS POST to https://kvpq6u62.instances.poc.jchunt.top/chromeos-webdriver-cli carrying installer-identifying fields (os.hostname(), platform, arch, node version, package name, timestamp). The destination is a hardcoded non-first-party host reached without user consent or configuration. The subdomain shape (random-token under instances.poc.jchunt.top) is consistent with a dependency-confusion / typo-squat canary beacon that discloses internal hostnames and environment metadata to a third party at install time.

Source: amazon-inspector (1bbf3413f6465a1f8bb628dcdb79f59ac7c197bbfba2024202c9915f95ad8161)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.