etoro-core@999.0.0
Vulnerability report · Last retrieved from osv.dev September 10, 2026 at 6:14 AM UTC
OSV ID
MAL-2026-16120
Ecosystem
npm
Summary
The package's preinstall lifecycle script (preinstall.js) issues an HTTP GET to the hardcoded bare-IP endpoint http://209.126.81.147/etoro-depconf-poce346552f776f/npm/ with os.hostname(), os.userInfo().username, and process.cwd() embedded in the URL path. This runs automatically on npm install and transmits installer host identity over plaintext HTTP to an attacker-controlled destination. The package name and inflated 999.0.0 version are consistent with a dependency-confusion payload targeting an internal etoro-core name.
Source: amazon-inspector (64a03f7bbaa2cb54ffea9a0c98d22bdc2fdb0d368846beefbd8d9c3b5ab3f644)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.