gaarf-node-bq @1.0.0
Vulnerability report · Last retrieved from osv.dev August 19, 2026 at 12:52 PM UTC
OSV ID
MAL-2026-14239
Ecosystem
npm
Summary
gaarf-node-bq is a dependency-confusion / typosquat canary targeting the internal google/ads-api-report-fetcher ( gaarf ) package. The bin entry is an empty noop and the package ships no real functionality. Its postinstall lifecycle script collects host identifiers (os.hostname(), platform, arch, node version, package name, npm lifecycle event) and POSTs them as JSON to the hardcoded endpoint https://yu7pug2j.instances.poc.jchunt.top/gaarf-node-bq. Any installer that mis-resolves the private name to the public registry has its host metadata sent to that endpoint without consent at install time.
Source: amazon-inspector (1f61e7b586146a833e50d74ccdff68942b4514f66c38beca981d2ead87761633)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.