Logo
npm

csa-mfa@1.1.16

Vulnerability report · Last retrieved from osv.dev September 16, 2026 at 3:27 AM UTC

Malicious

OSV ID

MAL-2026-16175

Ecosystem

npm

Summary

package.json declares a preinstall script that runs wget against http://169.58.142.14:8080/ with query parameters populated by shell command substitution of whoami, ls, and hostname. On npm install this automatically transmits the installer's username, current-directory listing, and hostname to a hardcoded bare-IP HTTP endpoint unrelated to any legitimate publisher infrastructure. There is no functional package purpose served by this behavior.

Source: amazon-inspector (959d2728ff38a804033ca7e07235b3a14bce65bd0e948077ba148a53c6cccff9)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.