Logo
npm

com.epi.e2e_test@1.2.2

Vulnerability report · Last retrieved from osv.dev September 30, 2026 at 5:15 PM UTC

Malicious

OSV ID

MAL-2026-17415

Ecosystem

npm

Summary

package.json declares a preinstall script that runs index.js on npm install. index.js collects host identifiers (os.homedir(), os.hostname(), os.userInfo().username, dns.getServers(), current working directory) along with the contents of the package.json and POSTs them over HTTPS to the hardcoded external host meta.brs.cx. This behavior fires automatically on install with no user interaction, and the collected data is characteristic of dependency-confusion / internal-name reconnaissance beacons used to identify targets for follow-on attacks.

Source: amazon-inspector (5a0c1068af335818f2b9d905f2d39ebe594f84a6c63e470877692554bc95103b)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.