com.epi.e2e_test@1.2.2
Vulnerability report · Last retrieved from osv.dev September 30, 2026 at 5:15 PM UTC
OSV ID
MAL-2026-17415
Ecosystem
npm
Summary
package.json declares a preinstall script that runs index.js on npm install. index.js collects host identifiers (os.homedir(), os.hostname(), os.userInfo().username, dns.getServers(), current working directory) along with the contents of the package.json and POSTs them over HTTPS to the hardcoded external host meta.brs.cx. This behavior fires automatically on install with no user interaction, and the collected data is characteristic of dependency-confusion / internal-name reconnaissance beacons used to identify targets for follow-on attacks.
Source: amazon-inspector (5a0c1068af335818f2b9d905f2d39ebe594f84a6c63e470877692554bc95103b)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.