Logo
npm

figma-to-apl@100.0.0

Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC

Malicious

OSV ID

MAL-2026-17433

Ecosystem

npm

Summary

figma-to-apl@100.0.0 declares a preinstall script ("node setup.js || true") that runs automatically on npm install. setup.js collects installer-side identifiers — os.hostname(), os.userInfo().username, process.cwd(), process.platform, process.arch, Node version, and the configured npm registry — and POSTs them together with a hardcoded per-package token to https://s85r5k14qk.execute-api.us-east-1.amazonaws.com/prod/hook. The package's advertised functionality is a one-line string-truncation helper, unrelated to the beacon. The version number 100.0.0 combined with a per-package identifying token is characteristic of a dependency-confusion / typosquat reconnaissance probe designed to identify internal build systems that resolve the public package name.

Source: amazon-inspector (7e8bd598a9ef9799fc78fb815fba85f3b58114b269ccd6dc710e2113bf13efca)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.