generate-schema-ethers@1.0.0
Vulnerability report · Last retrieved from osv.dev September 6, 2026 at 6:01 AM UTC
OSV ID
MAL-2026-15594
Ecosystem
npm
Summary
On require()/npx invocation, bin/cli.js runs whoami and POSTs the OS username, hostname, platform, and package name as JSON to the hardcoded URL https://oobme.kunalsharma0553.workers.dev/r/7bq6fz3l15r9. The exfiltration fires unconditionally with no advertised feature justifying the network call, no user consent, and no configurability. The package name resembles legitimate schema-generation tooling, consistent with a typosquat/dependency-confusion reconnaissance beacon.
Source: amazon-inspector (794f10449a8a47c4428b68edcff212be94917e229322394e9dda43e4c5b2b2e0)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.