npm

gaarf-node-bq @1.0.0

Vulnerability report · Last retrieved from osv.dev August 19, 2026 at 12:52 PM UTC

Malicious

OSV ID

MAL-2026-14239

Ecosystem

npm

Summary

gaarf-node-bq is a dependency-confusion / typosquat canary targeting the internal google/ads-api-report-fetcher ( gaarf ) package. The bin entry is an empty noop and the package ships no real functionality. Its postinstall lifecycle script collects host identifiers (os.hostname(), platform, arch, node version, package name, npm lifecycle event) and POSTs them as JSON to the hardcoded endpoint https://yu7pug2j.instances.poc.jchunt.top/gaarf-node-bq. Any installer that mis-resolves the private name to the public registry has its host metadata sent to that endpoint without consent at install time.

Source: amazon-inspector (1f61e7b586146a833e50d74ccdff68942b4514f66c38beca981d2ead87761633)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.