Logo
npm

efhthrthrthregerht@99.9.9

Vulnerability report · Last retrieved from osv.dev September 23, 2026 at 3:52 AM UTC

Malicious

OSV ID

MAL-2026-16436

Ecosystem

npm

Summary

The package's postinstall hook runs index.js, which collects the installer's OS username, current working directory, hostname, and local IPv4 address and POSTs them as JSON to a hardcoded webhook.site collector URL (https://webhook.site/f9bff304-3053-4d54-be05-86537267514a) on npm install. The package name is a random keyboard-mash string with no documented purpose, and the only on-install behavior is the outbound beacon to an anonymous ephemeral webhook endpoint controlled by whoever created the webhook.site token.

Source: amazon-inspector (4845639223c486cf2d33751ad950cea4c7f70401877929d25c36e7d07655d820)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.