figma-to-apl@100.0.0
Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC
OSV ID
MAL-2026-17433
Ecosystem
npm
Summary
figma-to-apl@100.0.0 declares a preinstall script ("node setup.js || true") that runs automatically on npm install. setup.js collects installer-side identifiers — os.hostname(), os.userInfo().username, process.cwd(), process.platform, process.arch, Node version, and the configured npm registry — and POSTs them together with a hardcoded per-package token to https://s85r5k14qk.execute-api.us-east-1.amazonaws.com/prod/hook. The package's advertised functionality is a one-line string-truncation helper, unrelated to the beacon. The version number 100.0.0 combined with a per-package identifying token is characteristic of a dependency-confusion / typosquat reconnaissance probe designed to identify internal build systems that resolve the public package name.
Source: amazon-inspector (7e8bd598a9ef9799fc78fb815fba85f3b58114b269ccd6dc710e2113bf13efca)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.