Logo
npm

faceplate-docs@99.9.10

Vulnerability report · Last retrieved from osv.dev September 23, 2026 at 3:52 AM UTC

Malicious

OSV ID

MAL-2024-2355

Ecosystem

npm

Summary

faceplate-docs@99.9.10 runs index.js from a postinstall hook that collects the installer's OS username, current working directory, hostname, and local IPv4 address and POSTs them as JSON to a hardcoded anonymous collector at https://webhook.site/f9bff304-3053-4d54-be05-86537267514a. The beacon fires automatically on npm install without any user interaction. The package name plus implausibly high version (99.9.10) and the recon-only payload are characteristic of a dependency-confusion probe designed to identify internal build environments that mistakenly resolve a private package name from the public registry.

Source: amazon-inspector (f5198954164869432a0fda9f3f723c1db53531ab2f73db84523e6f62946cf420)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.