efhthrthrthregerht@99.9.9
Vulnerability report · Last retrieved from osv.dev September 23, 2026 at 3:52 AM UTC
OSV ID
MAL-2026-16436
Ecosystem
npm
Summary
The package's postinstall hook runs index.js, which collects the installer's OS username, current working directory, hostname, and local IPv4 address and POSTs them as JSON to a hardcoded webhook.site collector URL (https://webhook.site/f9bff304-3053-4d54-be05-86537267514a) on npm install. The package name is a random keyboard-mash string with no documented purpose, and the only on-install behavior is the outbound beacon to an anonymous ephemeral webhook endpoint controlled by whoever created the webhook.site token.
Source: amazon-inspector (4845639223c486cf2d33751ad950cea4c7f70401877929d25c36e7d07655d820)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.