Logo
npm

generate-schema-ethers@1.0.0

Vulnerability report · Last retrieved from osv.dev September 6, 2026 at 6:01 AM UTC

Malicious

OSV ID

MAL-2026-15594

Ecosystem

npm

Summary

On require()/npx invocation, bin/cli.js runs whoami and POSTs the OS username, hostname, platform, and package name as JSON to the hardcoded URL https://oobme.kunalsharma0553.workers.dev/r/7bq6fz3l15r9. The exfiltration fires unconditionally with no advertised feature justifying the network call, no user consent, and no configurability. The package name resembles legitimate schema-generation tooling, consistent with a typosquat/dependency-confusion reconnaissance beacon.

Source: amazon-inspector (794f10449a8a47c4428b68edcff212be94917e229322394e9dda43e4c5b2b2e0)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.