etoro-analytics@999.0.0
Vulnerability report · Last retrieved from osv.dev September 10, 2026 at 6:14 AM UTC
OSV ID
MAL-2026-16112
Ecosystem
npm
Summary
The package's preinstall lifecycle script runs automatically on npm install and sends the installer's hostname, OS username, and current working directory to a hardcoded remote host at http://209.126.81.147 over plain HTTP, embedding the values as URL path segments under /etoro-depconf-poce346552f776f/npm/. The destination is a bare IP address, not configurable, and unrelated to any legitimate publisher infrastructure. The 999.0.0 version and eToro-themed name are consistent with a dependency-confusion lure targeting an internal package name.
Source: amazon-inspector (a87dfbd5f51b30470e8d1df702e746f7c8141fdaafab2237fd1f2ef4897d9ae5)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.